What is Detectify?

XSS

What’s your go-to bug class? Is it XSS? One could say cross-site scripting is a favourite among our researchers. Check it out:

How I made LastPass give me all your passwords

Cross Site Scripting Lastpass Mathias Karlsson XSS
bug bounty Bugcrowd Cross Site Scripting Frans Rosén XSS

Frans Rosén’s Bugcrowd Guest Blog: Using a Braun Shaver to Bypass XSS Audit and WAF

Chrome Cross Site Scripting Safari Twins of Ten XSS

Solutions to the Twins of Ten XSS Challenge

Get research and tips from Detectify security experts and the Crowdsource hacker community Subscribe to the Detectify Monthly Round-up
Cross Side Scripting Twins of Ten XSS

XSS challenge – Twins of Ten

Cross Site Scripting Google Turkey XSS

Google XSS Turkey

bug bounty Frans Rosén XSS

Building an XSS polyglot through SWF and CSP

Android Ethical Hacking XSS Zoho

Finding an XSS in an HTML-based Android application

Auditor bypass XSS

5 contexts where the XSS Auditor won’t help you

Chrome XSS

Chrome XSS Protection Bias (using Rails)

bug bounty XSS

How I got the Bug Bounty for Mega.co.nz XSS