cookie_crimes icon indicating copy to clipboard operation
cookie_crimes copied to clipboard

Not working on Windows 10 - Chrome 81.0.4044.138

Open physics-sec opened this issue 4 years ago • 3 comments

While the tool does outputs some cookies, this aren't really the cookies of the user. Chrome dev tools opens the page in some kind of container, without the user's cookies. The cookies it outputs are just the cookies that google sets automatically, without the user being logged in.

If you delete de --headeless parameter in the source code, run the tool and when chrome opens you go to http://localhsot:9222/json/new?https://some_page_you_are_logged_in.com you will see you are not going to be logged in this URL, that's why the tool can't retrieve the real cookies.

At least that is what I understood. Only tested in Windows 10, on the latest Chrome.

physics-sec avatar May 07 '20 17:05 physics-sec

BTW, i used the pull requests update that is not yet on the main branch to run it.

physics-sec avatar May 07 '20 17:05 physics-sec

Please you can see my repo works all version browser

https://github.com/hakanonymos/steal-chrome-password-all-version

hakanonymos avatar Jul 04 '20 05:07 hakanonymos

Well, It did work! very interesting work @hakanonymos , I will take a closer look!

physics-sec avatar Jul 04 '20 19:07 physics-sec