Cookie hijacking: Internet Explorer UXSS (CVE-2015-0072)
Host below files on webserver (attacker.com) and share the exploit link with victims,
exploit.php --- exploit link (Share with victim)
redirect.php --- Script to redirect on target page (target page should not contain X-Frame-Options or it will fail)
delay.php --- Script to add delay
collector.php --- Script to collect hijacked cookie
log.txt --- Collected cookies will be stored in this text file
-------------------------------------exploit.php-----------------------------------
--------------------------------------------------------------------------------------
-------------------------------------redirect.php-----------------------------------
--------------------------------------------------------------------------------------
-------------------------------------delay.php-----------------------------------
--------------------------------------------------------------------------------------
-------------------------------------collector.php-----------------------------------
--------------------------------------------------------------------------------------
-------------------------------------log.txt-----------------------------------
- Create a file as log.txt and modify the permissions (chmod 777 log.txt)
--------------------------------------------------------------------------------------
Demo: facabook.net16.net/exploit.php
Reference: http://innerht.ml/blog/ie-uxss.html