MrQ F1 — cross-site WebSocket hijack PoC (raw WebSocket)

Authorised testing only. Logged-in test account on an environment you own. This reads the victim's private socket data.
Opens a raw WebSocket (no SockJS /info, no CORS). Success depends on the SESSION cookie being sent: in Chrome a cross-site page will NOT send it (SameSite=Lax default) — test in Firefox, or host this page on a subdomain of the cookie site (mrq-test.com / mrq.live).
Scheme + host only, no path. Use the ws.* host from devtools, not app.*.
Auto-filled per target. /user/** is the victim's own private queue.