Okay I'm new to this site so I'm hoping me question doesn't come off as malicious. This is for school, so I'm not trying to do anything evil. Anyways, I was wondering if its possible to snatch a cookie using XSS, and deliver it to an attacker without sending it to an attacker controlled domain. Like if an attacker didn't own a domain, or if the domain was blocked, is there any other method or trick that can be used to recieve the cookie? I can code in Javascript relatively well, so you can talk about Javascript functions, methods etc. And thats encouraged because I'm interested in the coding perspective so please give me your ideas. Thanks.
