JavaScript È°¿ëÆÁ
2017.04.19 / 09:59

³×À̹ö ÀÚµ¿·Î±×ÀÎÇϱâ

1pips
Ãßõ ¼ö 221

³×À̹ö ÀÚµ¿·Î±×ÀÎÇϱâ

¸á·Ð¿¡ ÀÌ¾î ³×À̹ö ÀÚµ¿ ·Î±×ÀÎÇϱ⸦ ¸¸µé¾î º¸°Ú½À´Ï´Ù.

Àú¹ø°ú ¸¶Âù°¡Áö·Î Áñ°Üã±â¿¡ Ãß°¡ÇÏ´Â ¹æ½ÄÀ» ¾²°Ú´Âµ¥¿ä..

ã¾Æº¸´Ï Post ¹æ½ÄÀ¸·Î ID ¹× Password¸¦ º¸³»±â ¶§¹®¿¡ ´Ü¼øÈ÷ ÁÖ¼Ò¸¸À» Áñ°Üã±â¿¡ Ãß°¡Çؼ­´Â ÇÒ ¼ö°¡ ¾ø¾ú½À´Ï´Ù.

±×·¡¼­ »ç¿ëÇÑ ¹æ¹ý!!

À̸¥¹Ù ºÏ¸¶Å¬¸¯(Bookmarklet)!!

°£´ÜÈ÷ ¼³¸íµå¸®ÀÚ¸é JavascriptµîÀ» Áñ°Üã±â¿¡ Ãß°¡Çؼ­ »ç¿ëÇÏ´Â °ÍÀÌÁÒ.

¾Õ¿¡´Ù javascript: ¸¦ ºÙÀÎ ÈÄ µÚÀ̾î Javascript Source ¸¦ ³ÖÀ¸¸é µË´Ï´Ù.

¿¹¸¦ µéÀÚ¸é..

javascript:document.write('<html><head></head><body>TEST BOOKMAKLET</body></html>')
À» Áñ°Üã±â¿¡ Ãß°¡ÇÏ¸é ´Þ¶û

TEST BOOKMAKLET

Çϳª ³ª¿À´Â ÆäÀÌÁö°¡ ¶ã°Ì´Ï´Ù.


ÀÚ ±×·³ ÀÚµ¿·Î±×ÀÎ ÇÒ ¼ö ÀÖ°Ô ÇØÁÖ´Â javascript¸¦ ¸¸µé¾î¾ß°ÚÁÒ.

´ÙÀ½ÀÇ HTMLÀ» ±×´ë·Î javascript·Î ¸¸µé°Ú½À´Ï´Ù.
<html>
<head>
</head>
<body>
 <form id="testlogin" name="testlogin" target="_top" action="https://nid.naver.com/nidlogin.login" method="post">
  <input type="hidden" name="enctp" id="enctp" value="2">
  <input type="hidden" name="encpw" id="encpw" value="">
  <input type="hidden" name="encnm" id="encnm" value="">
  <input type="hidden" name="svctype" id="svctype" value="0">
  <input type="hidden" name="url" id="url" value="http://www.naver.com">
  <input type="hidden" name="enc_url" id="enc_url" value="http%3A%2F%2Fwww.naver.com">
  <input type="hidden" name="postDataKey" id="postDataKey" value="">
  <input type="hidden" name="saveID" id="saveID" value="">
  <input type="hidden" name="nvme" id="nvme" value="">
  <input type="hidden" name="id" id="uid" value="USER_ID">
  <input type="hidden" name="pw" id="upw" value="USER_PASSWORD">
 </form>
<script type="text/javascript"> 
 testlogin.submit();
</script>
 
</body>
</html>
 

À§ ³»¿ë Áß USER_ID¿¡´Â º»ÀÎÀÇ ID¸¦, USER_PASSWORD¿¡´Â º»ÀÎÀÇ Password¸¦ ³ÖÀ¸½Ã¸é µË´Ï´Ù.

ÀÌ·¸°Ô HTML ÆÄÀÏÀ» ¸¸µé¸é... ½ÇÇà ½ÃÄ×À» °æ¿ì ¹Ù·Î ·Î±×ÀÎ µÈ »óÅÂÀÇ ³×À̹ö°¡ ¶ß°Ô µË´Ï´Ù.

ÀÌÁ¦ ÀÌ°É javascript·Î ¸¸µé¸é..
javascript:document.write('<html><head></head><body><form id="testlogin" name="testlogin" target="_top" action="https://nid.naver.com/nidlogin.login" method="post">  <input type="hidden" name="enctp" id="enctp" value="2">  <input type="hidden" name="encpw" id="encpw" value="">  <input type="hidden" name="encnm" id="encnm" value="">  <input type="hidden" name="svctype" id="svctype" value="0">  <input type="hidden" name="url" id="url" value="http://www.naver.com">  <input type="hidden" name="enc_url" id="enc_url" value="http%3A%2F%2Fwww.naver.com">  <input type="hidden" name="postDataKey" id="postDataKey" value="">  <input type="hidden" name="saveID" id="saveID" value="">  <input type="hidden" name="nvme" id="nvme" value="">  <input type="hidden" name="id" id="uid" value="USER_ID">  <input type="hidden" name="pw" id="upw" value="USER_PASSWORD"> </form><script type="text/javascript">  testlogin.submit();</script> </body></html>')

ÀÌ°ÍÀ» º¹»çÇؼ­ Áñ°Üã±â¿¡ Ãß°¡ÇØÁÖ½Ã¸é µË´Ï´Ù.

¾Æ!! Áñ°Üã±â¿¡ Ãß°¡ÇÒ ¹æ¹ýÀº ÀÓÀÇ·Î Áñ°Üã±â¸¦ ¸¸µç ÈÄ ¼Ó¼º¿¡ °¡¼­ URL¿¡ º¹»çÇسÖÀ¸½Ã¸é µË´Ï´Ù.

±×·³ À̸¸...



Ãâó: http://injs2.tistory.com/entry/³×À̹ö-ÀÚµ¿·Î±×ÀÎÇϱâ [Don't give up]