Good technical write up on how this could be exploited