http://krebsonsecurity.com/2014/09/dread-pirate-sunk-by-leak...
Maybe he used a CAPTCHA library that generates absolute URLs using the server host name.
http://krebsonsecurity.com/2014/09/dread-pirate-sunk-by-leak...
Maybe he used a CAPTCHA library that generates absolute URLs using the server host name.