What is Detectify?

Frans Rosén

Dissecting the Chrome Extension Facebook malware

Chrome Chrome extensions Facebook Frans Rosén XSS
AWS bug bounty Frans Rosén privacy XSS

A deep dive into AWS S3 access controls – taking full control over your assets

bug bounty Frans Rosén Github Mathias Karlsson

BountyDash – A local bug bounty statistics dashboard

Frans Rosén postmessage Slack

Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token

bug bounty Fastly Frans Rosén Heroku Mathias Karlsson

Combining host header injection and lax host parsing serving malicious data

Frans Rosén Hostile Subdomain takeover SSL

The story of EV-SSL, AWS and trailing dot domains

Frans Rosén Slack XSS

Using Chrome’s web-custom-data UTI to inject a stored XSS in Slack

bug bounty Bugcrowd Cross Site Scripting Frans Rosén XSS

Frans Rosén’s Bugcrowd Guest Blog: Using a Braun Shaver to Bypass XSS Audit and WAF

Frans Rosén Patreon Remote Code Execution Werkzeug Debugger

How Patreon got hacked – Publicly exposed Werkzeug Debugger

bug bounty Frans Rosén XSS

Building an XSS polyglot through SWF and CSP