What is Detectify?

Writeups

What’s happening in Security? Detectify Labs is the home to novel security writeups from trusted security researchers active in the community. Contributors include Frans Rosén, Mathias Karlsson, Fredrik N. Almroth, and more.

CSP flaws: cookie fixation

Cookie fixation CSP Mathias Karlsson
AddThis Mathias Karlsson postmessage

postMessage XSS on a million sites

Mathias Karlsson postmessage

The pitfalls of postMessage

Get research and tips from Detectify security experts and the Crowdsource hacker community Time... to subscribe to the Detectify Monthly Round-up
bug bounty Fastly Frans Rosén Heroku Mathias Karlsson

Combining host header injection and lax host parsing serving malicious data

Frans Rosén Hostile Subdomain takeover SSL

The story of EV-SSL, AWS and trailing dot domains

Frans Rosén Slack XSS

Using Chrome’s web-custom-data UTI to inject a stored XSS in Slack

Cross Site Scripting Lastpass Mathias Karlsson XSS

How I made LastPass give me all your passwords

binary exploitation Fusion challenges return-oriented programming

Fusion Challenges – level02 Write-up

Slack Slackbots token

Slack bot token leakage exposing business critical information

bug bounty Bugcrowd Cross Site Scripting Frans Rosén XSS

Frans Rosén’s Bugcrowd Guest Blog: Using a Braun Shaver to Bypass XSS Audit and WAF