官术网_书友最值得收藏!

Protecting the cookies

Due to cookies being fully controllable from the client side, there are mechanisms to protect them from malicious modification:

  • Secure: This is a header flag that could be included in the application server when a cookie is sent by the HTTP response. It used to protect the cookie from channel interception. Basically, the use of this flag forces the applications to send cookies just for HTTPS connections.
  • HttpOnly: This is a flag included in the header's response to avoid scripting attacks to extract information from the cookies. For example, in the past, it was very common use cross-site scripting (XSS) attacks to extract information from cookies using JavaScript. Using HttpOnly, just the cookie could be consulted by the browser, and not by external scripts.

These controls can prevent some attacks, but what happens if the original application is doing an unexpected action while you have a session established with it? Is it possible? Yes, for sure, and it is not an error from the application's point of view.

主站蜘蛛池模板: 北辰区| 康马县| 土默特右旗| 建阳市| 开化县| 宣汉县| 平定县| 光泽县| 高邮市| 华阴市| 玉树县| 通山县| 承德市| 贵南县| 莱州市| 黔江区| 武功县| 洪洞县| 怀远县| 乌兰浩特市| 临朐县| 鹤壁市| 余庆县| 平罗县| 桂阳县| 东乡县| 东乌珠穆沁旗| 宁津县| 平阳县| 连江县| 汽车| 吉安市| 饶河县| 布尔津县| 稻城县| 西藏| 张家港市| 礼泉县| 惠安县| 蒙城县| 商洛市|