Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The exploit SWF just puts in that it is an Ajax call:

X-Requested-With: XMLHttpRequest

which says "I'm an AJAX request". Since the value is static, it is easy to use in an exploit.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: