What is Detectify?

Writeups

Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token

Frans Rosén postmessage Slack
Mathias Karlsson SQL Injection

SQLi in INSERT worse than SELECT

Stored XSS-ing Millions Of Sites Through HTML Comment Box

Cookie fixation CSP Mathias Karlsson

CSP flaws: cookie fixation

AddThis Mathias Karlsson postmessage

postMessage XSS on a million sites

Mathias Karlsson postmessage

The pitfalls of postMessage

bug bounty Fastly Frans Rosén Heroku Mathias Karlsson

Combining host header injection and lax host parsing serving malicious data

Frans Rosén Hostile Subdomain takeover SSL

The story of EV-SSL, AWS and trailing dot domains

Frans Rosén Slack XSS

Using Chrome’s web-custom-data UTI to inject a stored XSS in Slack

Cross Site Scripting Lastpass Mathias Karlsson XSS

How I made LastPass give me all your passwords