Collector Log
Payloads in the Live Output column run automatically in sandboxed iframes. Fetch and beacon calls appear here (auto-refreshes every 2 s).
Waiting for hits…
| Case | Name | Payload | Expected Behavior | Live Output |
|---|---|---|---|---|
| A1 | Script steals cookie | |
Crawler output should keep the script-looking text inert when displayed as HTML. | |
| A2 | Image onerror steals cookie | |
Crawler output should not render this as an executable image error handler. | |
| A3 | SVG onload steals cookie | |
Crawler output should not render this as an executable SVG load handler. | |
| A4 | Delayed cookie steal with setTimeout | |
Crawler output should keep delayed script text inert. |