creator Intigriti's March XSS challenge
By @LooseSecurity

Find a way to execute an alert(1337) utilising XSS on the challenge page and win Intigriti swag.

Rules:
  • This challenge runs from the 18th of March until the 26th of March, 11:59 PM UTC.
  • Out of all correct submissions, we will draw six winners on Wednesday, the 27th of March:
    • First blood
    • Three randomly drawn correct submissions
    • Three best write-ups
  • First blood will receive a €100 swag shop
  • Every other winner gets a €50 swag voucher for our swag shop
  • The winners will be announced on our Twitter profile.
  • For every 100 likes, we'll add a tip to announcement tweet.
  • Join our Discord to discuss the challenge!
The solution...
  • Should work on the latest version of Chrome and FireFox.
  • Should execute alert(1337).
  • Should leverage a cross site scripting vulnerability on this domain.
  • Shouldn't be self-XSS or related to MiTM attacks.
  • Should be reported at go.intigriti.com/submit-solution.
  • Should require no user interaction.
Test your payloads down below and on the challenge page here!

Let's pop that alert!