RSnake and Dan Kaminsky have been talking about session fixation via DNS Rebinding. As you may recall, an attacker can't abuse your Foo.com cookies in a rebinding attack, though they can walk your browser around Foo.com content and control the session. The gist of what these guys are talking about is how the attacker can log the victim into the attacker's session. Interesting stuff...
Dan and RSnake are big on server-side Host header validation as an anti-rebinding strategy. Every time I starting thinking about this, here's my basic train of thought:
Now, all this being said, I think the Rebinding threat is still yet to be fully defined. It's possible that some interesting anti-rebinding strategies we see will develop out of a need to address specific attack scenarios identified over time.