官术网_书友最值得收藏!

Protecting the cookies

Due to cookies being fully controllable from the client side, there are mechanisms to protect them from malicious modification:

  • Secure: This is a header flag that could be included in the application server when a cookie is sent by the HTTP response. It used to protect the cookie from channel interception. Basically, the use of this flag forces the applications to send cookies just for HTTPS connections.
  • HttpOnly: This is a flag included in the header's response to avoid scripting attacks to extract information from the cookies. For example, in the past, it was very common use cross-site scripting (XSS) attacks to extract information from cookies using JavaScript. Using HttpOnly, just the cookie could be consulted by the browser, and not by external scripts.

These controls can prevent some attacks, but what happens if the original application is doing an unexpected action while you have a session established with it? Is it possible? Yes, for sure, and it is not an error from the application's point of view.

主站蜘蛛池模板: 扎赉特旗| 望谟县| 酉阳| 扶沟县| 孝义市| 陆川县| 盖州市| 六安市| 布尔津县| 海南省| 达拉特旗| 瑞丽市| 织金县| 桓台县| 策勒县| 鹤岗市| 化德县| 广平县| 通榆县| 茌平县| 武威市| 天峨县| 芒康县| 新安县| 恩施市| 丰都县| 本溪| 阳江市| 商都县| 文山县| 白山市| 宝兴县| 永丰县| 墨竹工卡县| 镇巴县| 珠海市| 山阴县| 富锦市| 江阴市| 林芝县| 庄河市|