Hacker News new | ask | show | jobs
by homakov 4706 days ago
Untrustworthy scripts, HTML, images, email attachments.
1 comments

But I'm logged in! It shows myname in the corner. So obviously you could get that cookie, right?
Part with yourname is other_origin. I change content of GUC Page 2 using GUC Page 1 through other_origin (translate.google.com). No XSS or cookies. Just standards :D
I seriously admire your patience in replying to comments.
I have no life.
I was only referring to your continuing lengthy, polite comments when replying to commenters' questions. :)
:) it's pleasant to explain hacks you discover.

actually PoC is fixed - http://homakov.blogspot.com.es/2013/07/googleusercontentcom-...