December 26, 2021
During the week of Christmas 2021 the Belgian ethical hacking platform Intigriti hosted a new XSS (cross site scripting) challenge.
The POC video shows the local MAMP web server running my PHP redirect page to alter the referer HTML comment in the source code of the challenge page. Once the victim visits my webserver a redirect will happen towards the challenge page and the XSS attack will fire.
Embedded writeup PDF: