root@kali: ~/session_harvester — zsh
┌──(rootkali)-[~/session_harvester]
└─# ./harvest --live --collect :1337
LIVE captured: 0 last_sync: --:--:--
⚡ INJECTION PAYLOADS — copy into the vulnerable field
Auto-targeted at this console. Note: HttpOnly cookies are invisible to document.cookie — use the localStorage/token variants for those.
# timestamp (utc) source stolen session token user-agent / ip
[ awaiting incoming sessions... ]
endpoint: POST/GET /collect  ·  auto-refresh 5s  ·  loot.json  ·  click a row for detail  ·  SIMULATION — authorized use only