What is Detectify?
Detectify Labs
A security research blog
App Security
Writeups
How to
Crowdsource
Middleware, middleware everywhere – and lots of misconfigurations to fix
featured
Frans Rosén
load balancer
Mathias Karlsson
middleware vulnerabilities
misconfigurations
Nginx
Most read articles
How I made LastPass give me all your passwords
»
Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token
»
Chrome Extensions – AKA Total Absence of Privacy
»
How I hijacked the top-level domain of a sovereign state
ccTLD
DNS hijacking
Domain hijacking
featured
Fredrik Almroth
TLD takeover
Get research and tips from Detectify security experts and the Crowdsource hacker community
Time... to subscribe to the Detectify Monthly Round-up
Modern PHP Security Part 2: Breaching and hardening the PHP engine
PHP
Modern PHP Security Part 1: bug classes
featured
modern php
SQLi
SSRF
SSTI
How-to Tutorial: PHP Webshell De-Obfuscation
php malware
Investigation of PHP Web Shell Hexedglobals.3793 Variants
PHP
php malware
Thinking outside of the password manager box
password managers
Abuse MITM possible regardless of HTTPS
https
mitm
vpn
XSS using quirky implementations of ACME http-01
Auditor
Cross Site Scripting
Frans Rosén
HTTPS Everywhere
Linus Särud
validation
Bypassing and exploiting Bucket Upload Policies and Signed URLs
AWS
bug bounty
Frans Rosén
Google Cloud
s3 buckets
1
2
3
…
8
Next »
Like what you read? Start securing your web apps with tech powered by Detectify Labs contributors
Start a 2-week free trial of Detectify and see the difference for yourself