What is Detectify?
Detectify Labs
A security research blog
App Security
Writeups
How to
Crowdsource
CVE-2020-29653: Stealing Froxlor login credentials using dangling markup
0-day
CVE
Detectify Crowdsource
XSS
Most read articles
How I made LastPass give me all your passwords
»
Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token
»
Chrome Extensions – AKA Total Absence of Privacy
»
Middleware, middleware everywhere – and lots of misconfigurations to fix
Frans Rosén
load balancer
Mathias Karlsson
middleware vulnerabilities
misconfigurations
Nginx
Get research and tips from Detectify security experts and the Crowdsource hacker community
Subscribe to the Detectify Monthly Round-up
How I hijacked the top-level domain of a sovereign state
ccTLD
DNS hijacking
Domain hijacking
Fredrik Almroth
TLD takeover
Modern PHP Security Part 2: Breaching and hardening the PHP engine
PHP
Modern PHP Security Part 1: bug classes
modern php
SQLi
SSRF
SSTI
How-to Tutorial: PHP Webshell De-Obfuscation
php malware
Investigation of PHP Web Shell Hexedglobals.3793 Variants
PHP
php malware
Thinking outside of the password manager box
password managers
Abuse MITM possible regardless of HTTPS
https
mitm
vpn
XSS using quirky implementations of ACME http-01
Auditor
Cross Site Scripting
Frans Rosén
HTTPS Everywhere
Linus Särud
validation
« Previous
1
2
3
4
5
6
…
11
Next »
Start securing your web apps with tech powered by Detectify Crowdsource hackers
Start a 2-week free trial of Detectify and go hack yourself