Gist 6ed3f84640838d8320f6b209b1628e41
✓ Published0🌍 Public
PPeleke
Last edited Oct 5, 2018
Created on Oct 5, 2018
This example demonstrates a cross-site scripting (XSS) proof-of-concept that exfiltrates a visitor’s cookies. The code uses a raw JavaScript payload with `document.write` to inject an `<img>` tag, which fires a request to a user-supplied Ngrok URL, appending `document.cookie` as a query parameter. It shows a simple, direct attack vector for testing XSS vulnerabilities, relying on the browser’s automatic image request to send data to an external server. The visualization is the code itself, presented as a threat-modeling sample rather than a chart.
AI-generated description