← ChallengesMediumstored0/13 solved
mission · xss-stored-cookie-exfil

Cookie Thief

The admin of HackerMart is logged in. Their session cookie identifies them — and any script running on the site can read it. Post a guestbook comment that phones the admin's cookie home to your 'attacker server' when they visit.

objective

Steal the admin's session cookie by posting a stored payload, and watch it arrive at your listener.

🔒
HackerMartGuestbookcart · 0
Guestbook

Leave a comment about your shopping experience.

No comments yet. Be the first!

attacker.hp-lab.local — listening
Exfiltration log

No requests captured yet. Plant a payload that calls fetch()…

Simulated target for training. This page is the vulnerable website — payloads you craft execute here in your browser. Practice only on systems you own or are authorized to test.