What is Detectify?

Web security blog

How-to Tutorial: PHP Webshell De-Obfuscation

how to php malware tutorial

Investigation of PHP Web Shell Hexedglobals.3793 Variants

featured php malware

Thinking outside of the password manager box

password managers

Abuse MITM possible regardless of HTTPS

https mitm vpn

XSS using quirky implementations of ACME http-01

Auditor Cross Site Scripting Frans Rosén HTTPS Everywhere Linus Särud validation

Bypassing and exploiting Bucket Upload Policies and Signed URLs

AWS bug bounty Cloud Security Frans Rosén Google Cloud s3 buckets

The danger of recycled phone numbers

2fa phone number

Scratching the surface of host headers in Safari

host headers password managers Safari XSS

GraphQL abuse: Bypass account level permissions through parameter smuggling

Detectify Crowdsource

Changing the URL of social media sharing buttons

open redirect phishing social media