XSS
Medium · Stored XSS

Cookie Thief

The admin of HackerMart is logged in. Their session cookie identifies them — and any script running on the site can read it. Post a guestbook comment that phones the admin's cookie home to your 'attacker server' when they visit.

Objective

Steal the admin's session cookie by posting a stored payload, and watch it arrive at your listener.

Target

HackerMart

Launch target

Submit flag