Is not about arguing. As I said, even IF was a XSS attack that means he did something wrong on that machine / browser, is infected. That doesn't come from "doing nothing"...
No, as I and he said, XSS does not mean that.
reply