<?= $_SERVER['HTTP_REFERER']; ?>, then load http://www.whiteacid.org/misc/xss_headers.php?xss_target=http://127.0.0.1/show_ref.php&Referer= in IE and click the submit button, voila, you've loaded a page without a referer.
I'm sorry... I know it's 1:35am here, but that just makes no sense to me.Quote
And if you do that, you are risking that his XSS doesn't use the XSS you built in that localhost function to know a lot more about whatever you have running on localhost. ;)