Skip to content
 
DeteAct Pentest

Deteact – continuous information security services

Application Security, Penetration Testing, Security Consulting, Vulnerability Management, DDoS Testing, Threat Hunting, Awareness Training, Bug Bounty, Blockchain Security, Security Research

  • Services
  • About
  • Contact
  • Services
  • About
  • Contact
Bug Bounty Research Web SecurityLeave a comment

Common flaws of SMS auth

December 20, 2019December 20, 2019 beched

In Russian: https://blog.deteact.com/ru/common-flaws-of-sms-auth/ Many online services use SMS to authenticate users. But subtle implementation mistakes may lead to major problems. This is what we will talk about in this article. Intro This authentication protocol is

continue reading
Business News Research Web Securityapplication securitydqlphpzeronightsLeave a comment

ZeroNights 2019

November 15, 2019December 31, 2019 beched

This year’s ZeroNights conference was held on 12-13 November in Saint Petersburg. Our team participated in the Web Security Village, where Ramazan Ramazanov, a security researcher at DeteAct, presented his continued research about Doctrine Query

continue reading
Business News Research Web Securityapplication securityappsecdqlkazhackstanphpLeave a comment

KazHackStan 2019

October 21, 2019December 31, 2019 beched

Our team participated in the KazHackStan conference for the third time. We help the Call for Papers committee and presented our researches at this excellent conference in Kazakhstan. This year, Ramazan Ramazanov, a security researcher

continue reading
Research Web SecurityLeave a comment

Yandex.ClickHouse injection

September 5, 2019September 5, 2019 beched

In Russian: https://blog.deteact.com/ru/yandex-clickhouse-injection/ In order to process a large amount of data in Yandex.Metrika, Yandex created a column-oriented DBMS ClickHouse. During penetration tests, we encountered ClickHouse in the systems of statistics, event collection, stock exchange

continue reading
Web SecurityLeave a comment

DQL injection

July 29, 2019April 28, 2020 r0hack

In Russian: https://blog.deteact.com/ru/dql-injection Modern web applications are less prone to injections, everyone uses prepared queries and ORM, but we still encounter such vulnerabilities in the wild. SQL dialects built into ORM libraries are of particular

continue reading
Business News Research Web Securityapplication securityappsecoffzonevulnerability scannerweb application securityLeave a comment

OffZone 2019

June 21, 2019December 31, 2019 beched

Last year, the OffZone conference was held in November, and I (Omar Ganiev, CEO of DeteAct) presented a research about multi-layered web applications and their security issues. This year OffZone happened on 17-18 June, and

continue reading
Business News Researchapplication securityappsechealthcaremedical securitypentestphdaysLeave a comment

Positive Hack Days 2019

May 28, 2019December 31, 2019 beched

We’ve presented our products and services at the huge information security conference Positive Hack Days on 21-22 May in Moscow. Reports say, there were over 9000 participants this year.We were happy to have a chance

continue reading
Business NewsLeave a comment

Deteact’s profile at Y Combinator Startup School

January 11, 2019January 11, 2019 beched

Welcome back and check out our brief public profile at Y Combinator Startup School: https://www.startupschool.org/companies/deteact We graduated from the Advisor Track in November 2018. SUS gave us a lot of useful tips and hacks, sobering

continue reading
NewsLeave a comment

Deteact has been accepted into Y Combinator’s Startup School

August 28, 2018 beched

We’re happy to announce that Deteact has been accepted into the Advisor Track of Y Combinator’s Startup School! For the next 10 weeks, we will be a part of the group of 27 companies supervised by

continue reading
ToolsLeave a comment

Decompiling Ethereum smart contract ABI

August 20, 2018August 21, 2018 beched

Today there’s a number of publicly available EVM bytecode decompilers. However, many of them actually work only for toy examples and fail on real-world programs. This is one of the problems for Ethereum smart contracts

continue reading

Posts navigation

Older posts
Newer posts

Recent Posts

  • Security Audit of EAST Finance Protocol
  • Top-10 Penetration Testing Company
  • Leap Year for DeteAct
  • We won The Standoff
  • Account Takeover via IDOR

Archives

  • October 2021
  • August 2021
  • December 2020
  • November 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • July 2019
  • June 2019
  • May 2019
  • January 2019
  • August 2018
  • April 2018

Categories

  • Application Security
  • Bug Bounty
  • Business
  • CTF
  • Information
  • News
  • Press releases
  • Research
  • Services
  • Tools
  • Uncategorized
  • Web Security
Copyright © All right reserved.