WRITEUP | Intigriti Challenge-0221

Challenge by @holme_sec

First Look

Playing with the page

Injection (Or at least trying)

view-source:https://challenge-0221.intigriti.io/?assignmentTitle=AAAA%&assignmentText=AAAA
view-source:https://challenge-0221.intigriti.io/?assignmentTitle=AAAA%3C%20%3E%20%22%20&assignmentText=AAAA%3C%20%3E%20%22

Unicode?

view-source:https://challenge-0221.intigriti.io/?assignmentTitle=%E3%B0%80

Now What?

notice the ‘unsafe-eval’

Dom Clobbering

Final Payload: Execution

Fin

--

--

follow my twitter nerds https://twitter.com/CmdEngineer_

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store