What is Detectify?

Detectify Labs

A security research blog

SQLi in INSERT worse than SELECT

Mathias Karlsson SQL Injection

Stored XSS-ing Millions Of Sites Through HTML Comment Box

Get research and tips from Detectify security experts and the Crowdsource hacker community Subscribe to the Detectify Monthly Round-up

CSP flaws: cookie fixation

Cookie fixation CSP Mathias Karlsson

postMessage XSS on a million sites

AddThis Mathias Karlsson postmessage

The pitfalls of postMessage

Mathias Karlsson postmessage

Combining host header injection and lax host parsing serving malicious data

bug bounty Fastly Frans Rosén Heroku Mathias Karlsson

The story of EV-SSL, AWS and trailing dot domains

Frans Rosén Hostile Subdomain takeover SSL

Using Chrome’s web-custom-data UTI to inject a stored XSS in Slack

Frans Rosén Slack XSS

How I made LastPass give me all your passwords

Cross Site Scripting Lastpass Mathias Karlsson XSS

What HPKP is but isn’t

HPKP HTTP public key pinning
Start securing your web apps with tech powered by Detectify Crowdsource hackers Start a 2-week free trial of Detectify and go hack yourself