What is Detectify?

w3B s3CuR17y Bl09

How I hijacked the top-level domain of a sovereign state

ccTLD DNS hijacking Domain hijacking featured Fredrik Almroth TLD takeover

Modern PHP Security Part 2: Breaching and hardening the PHP engine


Modern PHP Security Part 1: bug classes

featured modern php SQLi SSRF SSTI

How-to Tutorial: PHP Webshell De-Obfuscation

php malware

Investigation of PHP Web Shell Hexedglobals.3793 Variants

PHP php malware

Thinking outside of the password manager box

password managers

Abuse MITM possible regardless of HTTPS

https mitm vpn

XSS using quirky implementations of ACME http-01

Auditor Cross Site Scripting Frans Rosén HTTPS Everywhere Linus Särud validation

Bypassing and exploiting Bucket Upload Policies and Signed URLs

AWS bug bounty Frans Rosén Google Cloud s3 buckets

The danger of recycled phone numbers

2fa phone number