What is Detectify?

XSS

What’s your go-to bug class? Is it XSS? One could say cross-site scripting is a favourite among our researchers. Check it out:

How To Hack Web Applications in 2022: Part 2

bug bounty Detectify Detectify Crowdsource Ethical Hacking hakluke XSS
bug bounty Detectify Crowdsource Frans Rosén OAuth postmessage XSS

Account hijacking using “dirty dancing” in sign-in OAuth-flows

Detectify Ethical Hacking hacking web apps XSS

How To Hack Web Applications in 2022: Part 1

Get research and tips from Detectify security experts and the Crowdsource hacker community Subscribe to the Detectify Monthly Round-up
0-day CVE Detectify Crowdsource XSS

CVE-2020-29653: Stealing Froxlor login credentials using dangling markup

host headers password managers Safari XSS

Scratching the surface of host headers in Safari

Chrome Chrome extensions Facebook Frans Rosén XSS

Dissecting the Chrome Extension Facebook malware

Tesla XSS

How we invented the Tesla DOM DOOM XSS

AWS bug bounty Frans Rosén privacy XSS

A deep dive into AWS S3 access controls – taking full control over your assets

Detectify Crowdsource Persistent XSS Team Tailor XSS

How I found a persistent XSS affecting thousands of career sites

Frans Rosén Slack XSS

Using Chrome’s web-custom-data UTI to inject a stored XSS in Slack