on Hacker News and reddit Previously I wrote how you can use XSS Auditor for Great Good(report to administrator about detected XSS exploits) and how to destroy framebrakers/other scirpts with it(just passing script's code in a random parameter). Today's topic is really interesting. We are not hacking XSS Auditor anymore, we are hacking with it. I'll tell you how to steal referers with sensitive in