What’s happening in Security? Detectify Labs is the home to novel security writeups from trusted security researchers active in the community. Contributors include Frans Rosén, Mathias Karlsson, Fredrik N. Almroth, and more.

Stored XSS-ing Millions Of Sites Through HTML Comment Box

Cookie fixation CSP Mathias Karlsson

CSP flaws: cookie fixation

AddThis Mathias Karlsson postmessage

postMessage XSS on a million sites

Mathias Karlsson postmessage

The pitfalls of postMessage

bug bounty Fastly Frans Rosén Heroku Mathias Karlsson

Combining host header injection and lax host parsing serving malicious data

Frans Rosén Hostile Subdomain takeover SSL

The story of EV-SSL, AWS and trailing dot domains

Frans Rosén Slack XSS

Using Chrome’s web-custom-data UTI to inject a stored XSS in Slack

Cross Site Scripting Lastpass Mathias Karlsson XSS

How I made LastPass give me all your passwords

binary exploitation Fusion challenges return-oriented programming

Fusion Challenges – level02 Write-up

Slack Slackbots token

Slack bot token leakage exposing business critical information