What is Detectify?

Writeups

What’s happening in Security? Detectify Labs is the home to novel security writeups from trusted security researchers active in the community. Contributors include Frans Rosén, Mathias Karlsson, Fredrik N. Almroth, and more.

How I hijacked the top-level domain of a sovereign state

ccTLD DNS hijacking Domain hijacking featured Fredrik Almroth TLD takeover
PHP php malware

Investigation of PHP Web Shell Hexedglobals.3793 Variants

AWS bug bounty Frans Rosén Google Cloud s3 buckets

Bypassing and exploiting Bucket Upload Policies and Signed URLs

Get research and tips from Detectify security experts and the Crowdsource hacker community Time... to subscribe to the Detectify Monthly Round-up
Detectify Crowdsource

GraphQL abuse: Bypass account level permissions through parameter smuggling

CSP Detectify Crowdsource Google Analytics

Using Google Analytics for data extraction

How I exploited ACME TLS-SNI-01 issuing Let’s Encrypt SSL-certs for any domain using shared hosting

Amazon PayPal Public Information Security Questions

Security Questions are not secure

Detectify Crowdsource Peter Jaric Selenium Grid

Guest Blog: Don’t Leave your Grid Wide Open

Chrome privacy Tinder

TrackMania – a Chrome plugin to stalk your friends on Tinder

Detectify Crowdsource DNS spoofing vulnerability

Guest blog: Bypassing domain control verification with DNS response spoofing