PDA

View Full Version : HttpOnly Cookies to Prevent XSS Attacks


Icheb
Mon 18th Sep '06, 8:34pm
In the announcement for 3.6.1 Kier mentions "HttpOnly Cookies to Prevent XSS Attacks". How exactly is that achieved? I would love to know how you guys implemented that.

Colin F
Tue 19th Sep '06, 8:17am
Internet Explorere introduced a tag for cookies called HttpOnly.
This prevents cookies from being called by JavaScript and thus reduces the risk of XSS attacks.

Icheb
Tue 19th Sep '06, 6:59pm
I have never heard of that before. Thank you!