Home / Companies / Detectify / Blog / July 2017

July 2017 Summaries

3 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
Detectify excels in External Attack Surface Management (EASM) by delivering highly accurate vulnerability assessments with a 99.7% accuracy rate. It is trusted by Product Security (ProdSec) and Application Security (AppSec) teams to reveal how attackers might target Internet-facing applications. The platform uses automation to simulate real-world, payload-based attacks, leveraging insights from a global community of elite ethical hackers to identify critical vulnerabilities before they can be exploited. Detectify offers a 2-week free trial for new users interested in exploring its capabilities.
Jul 26, 2017 62 words in the original blog post.
The Detectify Team has explored the vulnerabilities associated with AWS S3 storage misconfigurations, highlighting how they can be exploited by attackers to gain unauthorized access or control over data. AWS S3, a popular storage solution likened to a "Dropbox for IT and Tech teams," is known for its scalability and convenience, but misconfigurations can lead to significant security breaches. Attackers can use the AWS Command Line to exploit these vulnerabilities, potentially gaining the ability to list, read, upload, or modify files in an S3 bucket without the hosting company being aware. The text cites past examples, such as the Million Dollar Instagram Bug, to illustrate the potential impact of these security lapses, where unauthorized access to S3 buckets allowed researchers to impersonate users and access sensitive information. Detectify provides tools to scan for such vulnerabilities and offers guidance on securing S3 buckets by adjusting access privileges and maintaining awareness of potential security threats.
Jul 13, 2017 720 words in the original blog post.
Detectify is a leading platform in External Attack Surface Management (EASM) that offers highly accurate vulnerability assessments with a reported accuracy rate of 99.7%. It is trusted by Product Security (ProdSec) and Application Security (AppSec) teams to reveal how attackers might exploit their Internet-facing applications. The platform automates ongoing, real-world, payload-based attacks that are crowdsourced through a global network of elite ethical hackers, allowing organizations to uncover critical vulnerabilities proactively. Detectify offers a two-week free trial for new users interested in its services.
Jul 06, 2017 62 words in the original blog post.