What is Detectify?

Frans Rosén

Frans Rosén – Security Ninja; Security Advisor at Detectify. Here’s the archive of original security research which Frans Rosén has published.

Account hijacking using “dirty dancing” in sign-in OAuth-flows

bug bounty Detectify Crowdsource Frans Rosén OAuth postmessage XSS
Cloudkit Detectify Crowdsource Frans Rosén iOS

Hacking CloudKit – How I accidentally deleted your Apple Shortcuts

Frans Rosén load balancer Mathias Karlsson middleware vulnerabilities misconfigurations Nginx

Middleware, middleware everywhere – and lots of misconfigurations to fix

Get research and tips from Detectify security experts and the Crowdsource hacker community Subscribe to the Detectify Monthly Round-up
Auditor Cross Site Scripting Frans Rosén HTTPS Everywhere Linus Särud validation

XSS using quirky implementations of ACME http-01

AWS bug bounty Frans Rosén Google Cloud s3 buckets

Bypassing and exploiting Bucket Upload Policies and Signed URLs

Chrome Chrome extensions Facebook Frans Rosén XSS

Dissecting the Chrome Extension Facebook malware

AWS bug bounty Frans Rosén privacy XSS

A deep dive into AWS S3 access controls – taking full control over your assets

bug bounty Frans Rosén Github Mathias Karlsson

BountyDash – A local bug bounty statistics dashboard

Frans Rosén postmessage Slack

Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token

bug bounty Fastly Frans Rosén Heroku Mathias Karlsson

Combining host header injection and lax host parsing serving malicious data