Feed Sign in with OpenID OpenID

Simon Willison’s Weblog

Poking new holes with Flash Crossdomain Policy files. Very scary attack: if you can upload a file to a server, you can probably open it up to XSRF.

0 comments

No comments.

Sign in with OpenID

Auto-HTML: Line breaks are preserved; URLs will be converted in to links.

Manual XHTML: Enter your own, valid XHTML. Allowed tags are a, p, blockquote, ul, ol, li, dl, dt, dd, em, strong, dfn, code, q, samp, kbd, var, cite, abbr, acronym, sub, sup, br, pre

A django site