Home / Companies / Detectify / Blog / February 2017

February 2017 Summaries

9 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Detectify has received an update that enhances its security testing capabilities, focusing on vulnerabilities in various web platforms and applications. The latest release includes new tests for several WordPress vulnerabilities such as gadgetry XSS, SQL injection in wp-ultimate-form-builder, and open redirect in multi-device-switcher, among others. Additional security tests have been incorporated for YaBB and Ultimate Bulletin Board, addressing issues like reflected XSS and email disclosure. Other platforms such as Roxy File Manager, Piwik, KCEditor, and eXist also have new tests for vulnerabilities like open access, error information disclosure, and unauthenticated access. The update aims to help users stay informed and protected against a wide range of security threats.
Feb 28, 2017 107 words in the original blog post.
Incorporating security into agency offerings is essential not only for increasing revenue but primarily for ensuring client satisfaction and loyalty. As security becomes a more critical element in client relationships, agencies that proactively integrate security measures can distinguish themselves from competitors and foster long-term partnerships. This shift is driven by new legal guidelines, such as the General Data Protection Regulation, which mandates businesses to focus on preventive measures, and by market leaders like Google, which prioritize security in their services. Agencies can leverage tools like Detectify to conduct security tests, monitor vulnerabilities, and provide detailed reports, converting one-off projects into retainers and enhancing their service portfolio. The increased focus on security not only helps protect brand reputation by preventing breaches but also aligns with evolving digital marketing standards, where security is becoming as crucial as site speed and design. By adopting a security-oriented approach, agencies can achieve higher-value contracts and maintain a competitive edge in the rapidly changing digital landscape.
Feb 23, 2017 1,178 words in the original blog post.
Detectify is a leading platform in External Attack Surface Management (EASM), offering highly accurate vulnerability assessments with a 99.7% accuracy rate. It is trusted by ProdSec and AppSec teams to reveal potential exploitation methods for Internet-facing applications. The platform automates continuous, real-world, payload-based attack simulations that are crowdsourced from a global community of elite ethical hackers, aiming to uncover critical security weaknesses in a timely manner. Detectify offers a two-week free trial to new users, allowing them to experience its capabilities firsthand.
Feb 15, 2017 62 words in the original blog post.
The Detectify team embarked on a January retreat to Stockholm’s archipelago, where they engaged in a mix of team-building activities, workshops, and outdoor adventures. The excursion began with a trivia quiz and continued with exercises that tested both their teamwork and survival skills, such as making fire to brew coffee. Despite being web security experts rather than survivalists, the team embraced the challenge, creating memorable experiences like enjoying an unconventional fika and braving a sauna followed by a dip in an icy lake. The retreat concluded with a team dinner, a photo, and reflection sessions, leaving the team energized and eager to implement their plans for the year ahead. Detectify also extended an invitation to potential new team members to join their dynamic and adventurous workplace by exploring open positions on their careers page.
Feb 10, 2017 292 words in the original blog post.
Peter Jaric, a prominent figure in Sweden's developer community and a bug bounty hunter, shares his insights and experiences with bug bounty and responsible disclosure programs, highlighting how he transitioned from a long career in web development to legally engaging in hacking through these platforms. Jaric discusses his involvement with Detectify Crowdsource, noting its unique approach of focusing on common issues rather than specific vulnerabilities and its distinctive payout model that rewards contributors each time their identified issue is detected by the platform's scanner. He emphasizes the accessibility of participation in Crowdsource, encouraging new researchers to submit vulnerabilities without fear and praising the supportive nature of the Detectify staff. Jaric also reflects on his personal submissions, mainly centered on misconfigurations, and expresses his aspiration to identify a prevalent Remote Code Execution vulnerability as an ideal contribution to the program.
Feb 09, 2017 565 words in the original blog post.
Security is a dynamic field that requires continuous updates to address new vulnerabilities, which is why regular updates are crucial. Recent updates have highlighted several issues including SQL injection vulnerabilities in WMPL, cross-site scripting (XSS) in the Jetpack WordPress plugin, user enumeration via the WordPress REST API, and publicly exposed Predis example files. Other noted vulnerabilities include exposure of the Webalizer interface, remote code execution in Elasticsearch, discovering /.bash_history files, open memcache ports, and XSS issues with WordPress plupload.swf and wpml-plugin, along with an information disclosure module for /unzip.php. These updates aim to enhance security by addressing these vulnerabilities promptly.
Feb 03, 2017 90 words in the original blog post.
Andrea Palaia, a data scientist at Detectify, has a diverse and dynamic career that began with a fascination for theoretical physics during high school, leading him to pursue a PhD in accelerator physics and conduct research at CERN. His interest in data science was sparked during his PhD studies at Uppsala, where he conducted data analysis on large datasets from particle physics experiments. After completing his PhD, Andrea co-founded a startup focusing on plagiarism protection, which piqued his interest in the startup world. This led him to Detectify, where he joined as the sole member of the data team and built the data infrastructure from scratch, enjoying the creative freedom to shape the company's data processes. Andrea values the creative aspect of data analysis and relishes the opportunity to design solutions tailored to the company's needs. As Detectify has grown, Andrea anticipates the expansion of the data team, looking forward to a new phase of development. He is also passionate about sharing his knowledge through blogging and enjoys engaging with the broader data science community.
Feb 02, 2017 900 words in the original blog post.
The text is a comprehensive list of various online domains and URLs, reflecting a wide array of digital platforms and services that include analytics, advertising networks, social media, content delivery networks, and other web services. The extensive list covers popular platforms like Google Analytics, Facebook, Twitter, and Amazon, along with numerous lesser-known sites and services. It seems to be a snapshot or collection of data sources or endpoints that might be utilized for tracking, analytics, or content delivery purposes. The document also encourages further exploration and invites readers to share insights or engage in discussions on the topic.
Feb 02, 2017 2,818 words in the original blog post.
The article highlights the security risks associated with using third-party scripts on websites, emphasizing that vulnerabilities in imported resources can pose as much of a threat as vulnerabilities in a site's own code. The practice of including external scripts for added functionality is widespread, but it carries significant security concerns, such as the potential for cross-site scripting (XSS) attacks if a vulnerability is discovered in a commonly used script. The text underscores the importance of only using scripts from trusted third parties and keeping them updated, while acknowledging the dilemma between benefiting from auto-updates and the risks of external resources being tampered with. The article also discusses research that found a significant portion of the world's most popular domains rely on external resources, pointing out the security and privacy implications of this reliance. It calls for more discussion on these issues and provides statistics on the prevalence of external scripts, encouraging further exploration and dialogue in the web community.
Feb 02, 2017 1,170 words in the original blog post.