On Monday 23 December 2002 10:43 pm, Matthew Toseland wrote:
> Maybe we can just block link type=* ?
>
I get a feeling that that won't work.
I'm betting that a too-large contingent of browsers will either
1) reject the stylesheet outright if there isn't a type= in the link tag (I 
think maybe they're even supposed to do that),
or 2) treat the stylesheet as CSS regardless of both the type= and the 
mimetype (only IE comes to mind here, though -- although on first check, 
Konqy seems to do it as well -- at least for local docs. Will verify online 
soon.)

> ----- Forwarded message from Andrew Rodland <arodland at noln.com> -----
[summary of attack against anonymity filter using CSS and mimetype trickery]

_______________________________________________
devl mailing list
devl at freenetproject.org
http://hawk.freenetproject.org/cgi-bin/mailman/listinfo/devl

Reply via email to