What is Detectify?

Security

Bypassing and exploiting Bucket Upload Policies and Signed URLs

AWS bug bounty Cloud Security Frans Rosén Google Cloud s3 buckets
2fa phone number

The danger of recycled phone numbers

host headers password managers Safari XSS

Scratching the surface of host headers in Safari

open redirect phishing social media

Changing the URL of social media sharing buttons

How I exploited ACME TLS-SNI-01 issuing Let’s Encrypt SSL-certs for any domain using shared hosting

Chrome Chrome extensions Facebook Frans Rosén XSS

Dissecting the Chrome Extension Facebook malware

AWS bug bounty Frans Rosén privacy XSS

A deep dive into AWS S3 access controls – taking full control over your assets

bug bounty Frans Rosén Github Mathias Karlsson

BountyDash – A local bug bounty statistics dashboard

bug bounty Fastly Frans Rosén Heroku Mathias Karlsson

Combining host header injection and lax host parsing serving malicious data

HPKP HTTP public key pinning

What HPKP is but isn’t