He's a noob that found a list of the cross site scripting exploits on old versions of vB, pretty much if you're up to date his rants about insecurity are worthless.
The only thing he's somewhat right about is the cookie thing. If you log into your board on a public wireless network, anyone can sniff out your cookie without any problem. Once you that cookie is stolen they can do a lot of stuff without authorization until you change your password.
|