Simon Willison’s Weblog

Poking new holes with Flash Crossdomain Policy files. Very scary attack: if you can upload a file to a server, you can probably open it up to XSRF.