Hi, On 10/11, Christopher Allan Webber wrote: > The default in Guile has been to expose a port over localhost to which > code may be passed. The assumption for this is that only a local user > may write to localhost, so it should be safe. Unfortunately, users > simultaneously developing Guile and operating modern browsers are > vulnerable to a combination of an html form protocol attack  and a > DNS rebinding attack . How to combine these attacks is published in > the article "How to steal any developer's local database" .
Description: PGP signature