Showing source for: https://challenge-0522.intigriti.io/
Duration: 0.359809s

<!DOCTYPE html>
<html lang="en">
    <head>
        <meta content="text/html; charset=utf-8" http-equiv="Content-Type">
        <title>
   Intigriti May Challenge
        </title>
        <meta content="summary_large_image" name="twitter:card">
        <meta content="@intigriti" name="twitter:site">
        <meta content="@intigriti" name="twitter:creator">
        <meta content="May XSS Challenge - Intigriti" name="twitter:title">
        <meta content="Find the XSS and WIN Intigriti swag." name="twitter:description">
        <meta content="https://challenge-0522.intigriti.io/share.jpg" name="twitter:image">
        <meta content="https://challenge-0522.intigriti.io" property="og:url">
        <meta content="website" property="og:type">
        <meta content="May XSS Challenge - Intigriti" property="og:title">
        <meta content="Find the XSS and WIN Intigriti swag." property="og:description">
        <meta content="https://challenge-0522.intigriti.io/share.jpg" property="og:image">
        <link href="https://fonts.googleapis.com/css2?family=Poppins:wght@400;700&amp;display=swap" rel="stylesheet">
        <link href="style.css" rel="stylesheet">
        <!--[if gte mso 9]><xml>
<mso:CustomDocumentProperties>
<mso:MediaServiceImageTags msdt:dt="string"></mso:MediaServiceImageTags>
<mso:lcf76f155ced4ddcb4097134ff3c332f msdt:dt="string"></mso:lcf76f155ced4ddcb4097134ff3c332f>
<mso:TaxCatchAll msdt:dt="string"></mso:TaxCatchAll>
</mso:CustomDocumentProperties>
</xml><![endif]-->
    </head>
    <body>
        <section id="wrapper">
            <section id="rules">
                <div class="card-container" id="challenge-container">
                    <div class="card-header">
                        <img alt="creator" class="card-avatar" src="creator.jpg">
      Intigriti's May XSS challenge
                        <br>
                        By
                        <a href="https://twitter.com/PiyushThePal" target="_blank">
                            @PiyushThePal
                        </a>
                    </div>
                    <div class="card-content" id="challenge-info">
                        <p>
                            Find a way to execute arbitrary javascript on the iFramed page and win Intigriti swag.
                        </p>
                        <b>
                            Rules:
                        </b>
                        <ul>
                            <li>
                                This challenge runs from the 27th of May until the 2nd of June, 11:59 PM CET.
                            </li>
                            <li>
                                Out of all correct submissions, we will draw
                                <b>
                                    six
                                </b>
                                winners on Monday, the 3rd of June:
                                <ul>
                                    <li>
                                        Three randomly drawn correct submissions
                                    </li>
                                    <li>
                                        Three best write-ups
                                    </li>
                                </ul>
                            </li>
                            <li>
                                Every winner gets a &acirc;‚&not;50 swag voucher for our
                                <a href="https://swag.intigriti.com/" target="_blank">
                                    swag shop
                                </a>
                            </li>
                            <li>
                                The winners will be announced on our
                                <a href="https://twitter.com/intigriti" target="_blank">
                                    Twitter profile
                                </a>
                                .
                            </li>
                            <li>
                                For every 100 likes, we'll add a tip to
                                <a href="https://go.intigriti.com/challenge-tips" target="_blank">
                                    announcement tweet
                                </a>
                                .
                            </li>
                            <li>
                                Join our
                                <a href="https://go.intigriti.com/discord" target="_blank">
                                    Discord
                                </a>
                                to discuss the challenge!
                            </li>
                        </ul>
                        <b>
                            The solution...
                        </b>
                        <ul>
                            <li>
                                Should work on the latest version of Chrome
                                <b>
                                    and
                                </b>
                                FireFox.
                            </li>
                            <li>
                                Should execute
                                <code>
                                    alert(document.domain)
                                </code>
                                .
                            </li>
                            <li>
                                Should leverage a cross site scripting vulnerability on this domain.
                            </li>
                            <li>
                                Shouldn't be self-XSS or related to MiTM attacks.
                            </li>
                            <li>
                                Should not require any kind of user interaction. There should be a URL that when visited will present the victim with a popup
                            </li>
                            <li>
                                Should be reported at
                                <a href="https://go.intigriti.com/submit-solution">
                                    go.intigriti.com/submit-solution
                                </a>
                                .
                            </li>
                        </ul>
                        <b>
                            Test your payloads down below and
                            <a href="challenge/challenge.html">
                                on the challenge page here
                            </a>
                            !
                        </b>
                        <p>
                            Let's pop that alert!
                        </p>
                    </div>
                </div>
                <div class="card-container">
                    <iframe height="600px" src="challenge/challenge.html" width="100%">
                    </iframe>
                </div>
            </section>
        </section>
    </body>
</html>

Latest requests

# Url Url Source Date
1 https://challenge-0522.intigriti.i… 2025-02-11 11:18:38
2 https://thebolditalic.com/?gi=4c86… 2025-02-11 11:18:38
3 https://huxhemp.com/en-us/cbdfx-fu… 2025-02-11 11:18:37
4 https://boka.agoiare.se/(S(w1zjn5n… 2025-02-11 11:18:37
5 https://www.yesteks.com.tr/havlu-k… 2025-02-11 11:18:36
6 https://aukcjefilatelistyczne.pl/ 2025-02-11 11:18:34
7 https://thebolditalic.com/?gi=999f… 2025-02-11 11:18:33
8 https://agoiare.dlbookit.se/(S(m01… 2025-02-11 11:18:32
9 https://thebolditalic.com/?gi=1db6… 2025-02-11 11:18:32
10 https://agoiare.dlbookit.se/(S(mkr… 2025-02-11 11:18:30
11 https://theracalmcbdgummies.com/en… 2025-02-11 11:18:29
12 https://thebolditalic.com/?gi=b779… 2025-02-11 11:18:29
13 https://agoiare.dlbookit.se/(S(wxc… 2025-02-11 11:18:29
14 https://agoiare.dlbookit.se/(S(rtk… 2025-02-11 11:18:25
15 https://thebolditalic.com/?gi=b010… 2025-02-11 11:18:23
16 https://www.spgrrok.catholic.edu.a… 2025-02-11 11:18:23
17 https://agoiare.dlbookit.se/(S(svu… 2025-02-11 11:18:22
18 https://huxhemp.com/en-us/sivan-sl… 2025-02-11 11:18:20
19 https://thebolditalic.com/?gi=bce5… 2025-02-11 11:18:19
20 https://thebolditalic.com/?gi=de64… 2025-02-11 11:18:18