Metro by T-Mobile — refer.metrobyt-mobile.com DOM XSS via buyapowa:sso_redirect

Usage: append ?uuid=<your-webhook.site-uuid> to this page's URL. Sign in to a Metro account first, then click the button. Stolen cookies / storage are POSTed to https://webhook.site/<uuid> and also echoed below.

Status: idle

Ready-to-send request — built on the Metro origin from the stolen cookies

The payload reads the apex-scoped, non-HttpOnly a_token, l3Token and MyTMobile cookies and assembles this request. Paste it straight into Caido / Burp Repeater — no other setup needed.

(nothing yet)


Full exfiltrated blob

(nothing yet)

Payload posted to the Metro window