- 13
- OAUTH2
- 조회 수 201
스포어는 GET요청를 https://studyforus.com/index.php?act=dispMemberLogout
여기에 보내면 로그아웃입니다.
따라서
<iframe width="560" height="315" src="https://studyforus.com/index.php?act=dispMemberLogout"></iframe>
이런식으로 동영상을 삽입하면 작성자가 로그아웃....
하지만 작성만 가능하다면 보는사람을 로그아웃 시킬수 있습니다. .....
참조:https://studyforus.com/freeboard/441898
댓글 13
![profile image](/files/member_extra_info/profile_image/640/096/96640.gif?t=1548527149)
![comment menu](/modules/board/skins/comely_board/images/icn_more.png)
2018.10.31. 18:03
이건 계정 탈퇴인가요?
![comment menu](/modules/board/skins/comely_board/images/icn_more.png)
2018.10.31. 18:08
![profile image](/files/member_extra_info/profile_image/640/096/96640.gif?t=1548527149)
네 ㅋㅋㅋ
![comment menu](/modules/board/skins/comely_board/images/icn_more.png)
2018.10.31. 19:06
![profile image](/files/member_extra_info/profile_image/845/172/172845.png?t=1690820334)
누르면 바로 탈퇴되는 건가요 ㄷㄷㄷ
![comment menu](/modules/board/skins/comely_board/images/icn_more.png)
2018.10.31. 19:09
![profile image](/files/member_extra_info/profile_image/640/096/96640.gif?t=1548527149)
아뇨. 비밀번호 한번 입력해야 돼요.
![comment menu](/modules/board/skins/comely_board/images/icn_more.png)
2018.10.31. 19:25
![profile image](/files/member_extra_info/profile_image/845/172/172845.png?t=1690820334)
다행이군요 ㅋㅋㅋ
![comment menu](/modules/board/skins/comely_board/images/icn_more.png)
2018.10.31. 19:34
![profile image](/files/member_extra_info/profile_image/640/096/96640.gif?t=1548527149)
누르는 순간 바로 탈퇴되도록하면 정말 위험하죠. ㅋㅋㅋㅋㅋㅋ
![comment menu](/modules/board/skins/comely_board/images/icn_more.png)
2018.10.31. 19:38
![profile image](/files/member_extra_info/profile_image/145/220/220145.jpg?t=1603012768)
그누보드 SNS로그인 플러그인에 해당 취약점이 있었죠ㅋㅋ
소셜로그인 계정 한정으로...
![comment menu](/modules/board/skins/comely_board/images/icn_more.png)
2018.10.31. 20:15
![profile image](/files/member_extra_info/profile_image/640/096/96640.gif?t=1548527149)
취약점이 있었다는 이야기는 들었는데 이거 였군요!
![comment menu](/modules/board/skins/comely_board/images/icn_more.png)
2018.10.31. 23:16
index.php 뒤에 act 값만 붙여주시면 됩니다.
로그인버튼.로그아웃.회원탈퇴 등등 다양하게 만들수 있죠.ㅋ
![comment menu](/modules/board/skins/comely_board/images/icn_more.png)
2018.10.31. 22:40
허어어어억
![comment menu](/modules/board/skins/comely_board/images/icn_more.png)
2018.11.01. 01:11
대부분 웹사이트가 로그아웃 CSRF 공격에 대해서는 취약하죠.
![comment menu](/modules/board/skins/comely_board/images/icn_more.png)
2018.11.03. 13:56
권한이 없습니다.
https://studyforus.com/index.php?act=dispMemberLeave
※주의!