fair enough, didnt think anyone would show how its done.
but knowing that all versions are vunerable as long as HTML is enabled is good to know, as now I will ALWAYS turn off HTML.
Still dont really understand how you can steal the cookies from a remote script running local to the forum :ermm: ah well, i'll learn more soon, and maybe understand the why it works?...
|