Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Here's Mozilla's linked post on this, from March of this year - http://blog.mozilla.com/security/2010/03/31/plugging-the-css...

To support your statement, I haven't found anything saying this has been removed.



There seems to be a partial fix in the 4.0 codebase: https://bugzilla.mozilla.org/show_bug.cgi?id=147777#c259


Yeah, sites like http://www.didyouwatchporn.com/ and http://ha.ckers.org/weird/CSS-history-hack.html fail to work in Firefox 4. The followup bugs are more to do with tuning what is allowed and what isn't, e.g. https://bugzilla.mozilla.org/show_bug.cgi?id=559722.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: