the whole world burns

More CSRF issues with Flash crossdomain policy files

 # [via]

More and more, web app security looks like a house of cards.

forging arbitrary HTTP request headers with Flash

 #

That's a pretty nasty vulnerability.

What the devil?

The Whole World Burns is the rephrase miniblog, containing links and other miscellaneous trifles.