What is Detectify?
Detectify Labs
A security research blog
App Security
Writeups
How to
Crowdsource
SQLi in INSERT worse than SELECT
Mathias Karlsson
SQL Injection
Most read articles
How I made LastPass give me all your passwords
»
Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token
»
Chrome Extensions – AKA Total Absence of Privacy
»
Stored XSS-ing Millions Of Sites Through HTML Comment Box
Get research and tips from Detectify security experts and the Crowdsource hacker community
Subscribe to the Detectify Monthly Round-up
CSP flaws: cookie fixation
Cookie fixation
CSP
Mathias Karlsson
postMessage XSS on a million sites
AddThis
Mathias Karlsson
postmessage
The pitfalls of postMessage
Mathias Karlsson
postmessage
Combining host header injection and lax host parsing serving malicious data
bug bounty
Fastly
Frans Rosén
Heroku
Mathias Karlsson
The story of EV-SSL, AWS and trailing dot domains
Frans Rosén
Hostile Subdomain takeover
SSL
Using Chrome’s web-custom-data UTI to inject a stored XSS in Slack
Frans Rosén
Slack
XSS
How I made LastPass give me all your passwords
Cross Site Scripting
Lastpass
Mathias Karlsson
XSS
What HPKP is but isn’t
HPKP
HTTP public key pinning
« Previous
1
…
5
6
7
8
9
…
11
Next »
Start securing your web apps with tech powered by Detectify Crowdsource hackers
Start a 2-week free trial of Detectify and go hack yourself