What is Detectify?

XSS

Dissecting the Chrome Extension Facebook malware

Chrome Chrome extensions Facebook Frans Rosén XSS
Tesla XSS

How we invented the Tesla DOM DOOM XSS

AWS bug bounty Frans Rosén privacy XSS

A deep dive into AWS S3 access controls – taking full control over your assets

Detectify Crowdsource Persistent XSS Team Tailor XSS

How I found a persistent XSS affecting thousands of career sites

Frans Rosén Slack XSS

Using Chrome’s web-custom-data UTI to inject a stored XSS in Slack

Cross Site Scripting Lastpass Mathias Karlsson XSS

How I made LastPass give me all your passwords

bug bounty Bugcrowd Cross Site Scripting Frans Rosén XSS

Frans Rosén’s Bugcrowd Guest Blog: Using a Braun Shaver to Bypass XSS Audit and WAF

Chrome Cross Site Scripting Safari Twins of Ten XSS

Solutions to the Twins of Ten XSS Challenge

Cross Side Scripting Twins of Ten XSS

XSS challenge – Twins of Ten

Cross Site Scripting Google Turkey XSS

Google XSS Turkey