What is Detectify?

Detectify Labs

A security research blog

What is a Prototype Pollution vulnerability and how does page-fetch help?

client-side page-fetch prototype pollution tools

Detectify releases Ugly Duckling, an open-source web scanner for ethical hackers

Detectify Crowdsource open-source scanner
Get research and tips from Detectify security experts and the Crowdsource hacker community Time... to subscribe to the Detectify Monthly Round-up

CVE-2020-29653: Stealing Froxlor login credentials using dangling markup

0-day CVE Detectify Crowdsource XSS

Middleware, middleware everywhere – and lots of misconfigurations to fix

featured Frans Rosén load balancer Mathias Karlsson middleware vulnerabilities misconfigurations Nginx

How I hijacked the top-level domain of a sovereign state

ccTLD DNS hijacking Domain hijacking featured Fredrik Almroth TLD takeover

Modern PHP Security Part 2: Breaching and hardening the PHP engine

PHP

Modern PHP Security Part 1: bug classes

featured modern php SQLi SSRF SSTI

How-to Tutorial: PHP Webshell De-Obfuscation

php malware

Investigation of PHP Web Shell Hexedglobals.3793 Variants

PHP php malware

Thinking outside of the password manager box

password managers
Like what you read? Start securing your web apps with tech powered by Detectify Labs contributors Start a 2-week free trial of Detectify and see the difference for yourself