Lycos runs a free mail service on Lycos of course also has an address book, which lives at . If I'm composing a mail and want to fetch an address from my address book, a simple JavaScript copies the address from the address book to the "To" field of the new E-mail.

The problem with that is that it is a basic security measure of JavaScript that scripts are not allowed to work across different domains.

To the browser, and are two different sites. Lycos changes the document.domain to avoid security restrictions but ..

1) They do so only after some browser sniffing that means nothing happens if you identify as Opera.

2) The mail does not have any port number in the address, while the address book has. Thus the scripts still fail the origin check.

The first point is definitely a bug in Lycos's script. The second is probably a bug in Opera – we are "too secure" for sites that really do their best to look like they are performing cross-domain JavaScript attacks…

