Description

Pop an alert containing document.domain on https://challenge-0424.intigriti.io and win Intigriti swag. This is a guest challenge created by kire_devs_hacks: https://twitter.com/kire_devs_hacks

Bounties

This is a responsible disclosure program without bounties.

Rules of engagement
Not applicable
Not applicable
Not applicable
Not applicable

N/A

Domains

challenge-0424.intigriti.io

Tier 2
URL
In scope

Go to the challenge

Rules:

  • Please do NOT reveal the solution until the challenge is over! After that, feel free to send us your videos / writeups and we'll share them. If you'd like to have your writeup qualify for the contest, send it in before Wednesday!
  • This challenge runs from Monday the 8th of April until Monday the 15th of April, 11:59 PM UTC..
  • Out of all correct submissions, we will announce seven winners on Tuesday, the 16th of April: (3 randomly drawn, 3 best write-ups, 1 first blood)
  • First blood will receive a €100 swag voucher for our swag shop.
  • Every randomly drawn winner and best writeup winner gets a €50 swag voucher for our swag shop.
  • The winners will be announced on our Twitter profile.
  • For every 100 likes, we'll add a tip to the announcement tweet.
  • Join our Discord server to discuss the challenge!

The solution...

  • Should work on the latest version of Chrome (Firefox not required).
  • Should execute alert(document.domain).
  • Should leverage a cross site scripting vulnerability on this domain.
  • Shouldn't be self-XSS or related to MiTM attacks.
  • Should be reported at go.intigriti.com/submit-solution.
  • Should require no user interaction.

For the writeup content, make sure to add a (hidden) link to your writeup in the report or comments before the challenge has ended!

If you wish to get @'ed on Twitter, link your Twitter with your Intigriti profile!

Out of scope

N/A

Severity assessment

Please submit as medium.

FAQ

N/A

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.

Program specifics
no reputation No collaboration
no reputation Not managed by Intigriti
Researchers
last contributors
logo
logo
logo
logo
logo
logo
leaderboard
logo
logo
logo
logo
logo
logo
Overall stats
submissions received
18
average payout
N/A
accepted submissions
16
total payouts
N/A
Last 90 day response times
avg. time first response
< 24 hours
avg. time to decide
< 2 days
Activity
4/17
intigriti
closed a submission
4/17
intigriti
closed a submission
4/17
intigriti
closed a submission
4/17
intigriti
closed a submission
4/17
intigriti
closed a submission
4/16
intigriti
suspended the program
4/16
intigriti
accepted a submission
4/16
intigriti
accepted a submission
4/16
intigriti
accepted a submission
4/16
intigriti
accepted a submission