Acme Dashboard
Role: VICTIM website. This domain plays the vulnerable web
application in the serialize-javascript proof of concept (Intigriti report
evidence). The pages below embed serialized output produced by
serialize-javascript@7.1.2 from a spoofed
toString() function; the payload executes when the browser
parses the output.
Security research PoC. All "victim" state is synthetic
(demo session cookie, fake JWT, fake CSRF token) and is exfiltrated
cross-origin to the researcher's separate ATTACKER site. Do not enter real
credentials anywhere on this domain.
Pages
- poc-embed.html - execution at parse time via
plain script embedding, zero eval calls. Markers: title becomes
EMBED-ALONE-EXECUTED, window.__embedRan === true,
typeof data.calc === "number".
- poc-exfil.html - same parse-time execution;
silently exfiltrates the cookie jar, localStorage and sessionStorage to the
attacker site configured in the one
window.__collector line of
the page source.