What is Detectify?

Writeups

What’s happening in Security? Detectify Labs is the home to novel security writeups from trusted security researchers active in the community. Contributors include Frans Rosén, Mathias Karlsson, Fredrik N. Almroth, and more.

Common Security Vulnerabilities in Core AWS Services: Exploitation and Mitigation

Amazon web services AWS aws attack AWS security assessment AWS services Detectify
bug bounty Detectify Crowdsource Frans Rosén OAuth postmessage XSS

Account hijacking using “dirty dancing” in sign-in OAuth-flows

Cloudkit Detectify Crowdsource Frans Rosén iOS

Hacking CloudKit – How I accidentally deleted your Apple Shortcuts

Get research and tips from Detectify security experts and the Crowdsource hacker community Subscribe to the Detectify Monthly Round-up
api fuzzing api security pentesting

Go Fuzz Yourself – How to Find More Vulnerabilities in APIs Through Fuzzing [Whitepaper download]

ccTLD DNS hijacking Domain hijacking Fredrik Almroth TLD takeover

How I hijacked the top-level domain of a sovereign state

PHP php malware

Investigation of PHP Web Shell Hexedglobals.3793 Variants

AWS bug bounty Frans Rosén Google Cloud s3 buckets

Bypassing and exploiting Bucket Upload Policies and Signed URLs

Detectify Crowdsource

GraphQL abuse: Bypass account level permissions through parameter smuggling

CSP Detectify Crowdsource Google Analytics

Using Google Analytics for data extraction

How I exploited ACME TLS-SNI-01 issuing Let’s Encrypt SSL-certs for any domain using shared hosting