What is Detectify?
w3B s3CuR17y Bl09
Security
Writeups
How to
Detectify
How I hijacked the top-level domain of a sovereign state
ccTLD
DNS hijacking
Domain hijacking
featured
Fredrik Almroth
TLD takeover
Most read articles
How I made LastPass give me all your passwords
»
Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token
»
Chrome Extensions – AKA Total Absence of Privacy
»
Modern PHP Security Part 2: Breaching and hardening the PHP engine
PHP
Modern PHP Security Part 1: bug classes
featured
modern php
SQLi
SSRF
SSTI
How-to Tutorial: PHP Webshell De-Obfuscation
php malware
Investigation of PHP Web Shell Hexedglobals.3793 Variants
PHP
php malware
Thinking outside of the password manager box
password managers
Abuse MITM possible regardless of HTTPS
https
mitm
vpn
XSS using quirky implementations of ACME http-01
Auditor
Cross Site Scripting
Frans Rosén
HTTPS Everywhere
Linus Särud
validation
Bypassing and exploiting Bucket Upload Policies and Signed URLs
AWS
bug bounty
Frans Rosén
Google Cloud
s3 buckets
The danger of recycled phone numbers
2fa
phone number
1
2
3
…
8
Next »