Description

Find the FLAG on https://challenge-0325.intigriti.io and win Intigriti swag!

Bounties

This is a responsible disclosure program without bounties.

Rules of engagement
Not applicable
Not applicable
Not applicable
Not applicable

N/A

Domains
In scope

Go to the challenge

Rules:

  • Please do NOT reveal the solution until the challenge is over! After that, feel free to send us your videos / writeups and we'll share them. If you'd like to have your writeup qualify for the contest, send it in before Monday!
  • This challenge runs from Monday the 24th of March until Sunday the 30th of March, 11:59 PM UTC.
  • Out of all correct submissions, we will announce seven winners on Monday, the 31st of March: (3 randomly drawn, 3 best write-ups, 1 first blood)
  • First blood will receive a €100 swag voucher for our swag shop.
  • Every randomly drawn winner and best writeup winner gets a €50 swag voucher for our swag shop.
  • The winners will be announced on our Twitter profile.
  • For every 50 likes, we'll add a tip to the announcement tweet.
  • Join our Discord server to discuss the challenge!

The solution...

  • Should find the FLAG.
  • Should work on the latest version of Chromium and Firefox.
  • Should leverage a cross site scripting vulnerability on this domain.
  • Shouldn't be self-XSS or related to MiTM attacks.
  • Should be reported at submit solution.

For the writeup content, make sure to add a (hidden) link to your writeup in the report or comments before the challenge has ended! We'll link them on our gitbook afterwards.

If you wish to get @'ed on Twitter, link your Twitter with your Intigriti profile!

Out of scope

N/A

Severity assessment

Please submit as medium.

FAQ

N/A

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.

Program specifics
No collaboration
Not managed by Intigriti
Overall stats
submissions received
7
average payout
N/A
accepted submissions
5
total payouts
N/A
Last 90 day response times
avg. time first response
< 8 hours
avg. time to decide
< 16 hours
Activity
3/27
logo
tarampampam
created a submission
3/27
intigriti
closed a submission
3/27
intigriti
accepted a submission
3/27
intigriti
accepted a submission
3/27
logo
antonio
created a submission
3/27
intigriti
accepted a submission
3/27
logo
panya
created a submission
3/27
logo
disna
created a submission
3/26
logo
adragos
created a submission
3/25
intigriti
accepted a submission