Description

Pop an alert containing document.domain on https://challenge-1224.intigriti.io and win Intigriti swag!

Bounties

This is a responsible disclosure program without bounties.

Rules of engagement
Not applicable
Not applicable
Not applicable
Not applicable

N/A

Domains
In scope

Go to the challenge

Rules:

  • Please do NOT reveal the solution until the challenge is over! After that, feel free to send us your videos / writeups and we'll share them. If you'd like to have your writeup qualify for the contest, send it in before Thursday!
  • This challenge runs from Wednesday the 11th of December until Wednesday the 18th of December, 11:59 PM UTC.
  • Out of all correct submissions, we will announce eleven winners on Thursday, the 19th of December: (5 randomly drawn, 5 best write-ups, 1 first blood)
  • First blood will receive a €100 swag voucher for our swag shop.
  • Every randomly drawn winner and best writeup winner gets a €50 swag voucher for our swag shop.
  • The winners will be announced on our Twitter profile.
  • For every 100 likes, we'll add a tip to the announcement tweet.
  • Join our Discord server to discuss the challenge!

The solution...

  • Should execute alert(document.domain).
  • Should work on the latest version of Chrome and FireFox.
  • Should leverage a cross site scripting vulnerability on this domain.
  • Shouldn't be self-XSS or related to MiTM attacks.
  • Should require no user interaction.
  • Should be reported at go.intigriti.com/submit-solution.

For the writeup content, make sure to add a (hidden) link to your writeup in the report or comments before the challenge has ended! We'll link them on our gitbook afterwards.

If you wish to get @'ed on Twitter, link your Twitter with your Intigriti profile!

Out of scope

oos.png
{308374} 12/11/2024, 9:54:08 AM
Severity assessment

Please submit as medium severity.

FAQ

N/A

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.

Program specifics
No collaboration
Not managed by Intigriti
Overall stats
submissions received
14
average payout
N/A
accepted submissions
12
total payouts
N/A
Last 90 day response times
avg. time first response
< 8 hours
avg. time to decide
< 8 hours
Activity
12/18
intigriti
accepted a submission
12/18
logo
sebsrt
created a submission
12/18
intigriti
accepted a submission
12/18
logo
securaji
created a submission
12/18
intigriti
accepted a submission
12/18
logo
kukainis
created a submission
12/17
logo
cozyfox
created a submission
12/17
intigriti
accepted a submission
12/17
intigriti
accepted a submission
12/17
logo
domons
created a submission