This article is a mirror article of machine translation, please click here to jump to the original article.

View: 14404|Reply: 0

[Safety Knowledge] How do I set HttpOnly for cookies? What is HttpOnly used for?

[Copy link]
Posted on 9/18/2016 3:28:30 PM | | |
In the field of web security, cross-site scripting attacks are the most common form of attack, and it has been a long-standing problem, and this article will introduce readers to a technology to alleviate this pressure, namely HTTP-only cookies.

1. Introduction to XSS and HTTP-only Cookies
Cross-site scripting attacks are one of the common problems plaguing web server security. Cross-site scripting attacks are a server-side security vulnerability that is often caused by server-side failure to properly filter user input when submitted as HTML. Cross-site scripting attacks can cause sensitive information of website users to be leaked. To reduce the risk of cross-site scripting attacks, Microsoft's Internet Explorer 6 SP1 introduces a new feature.

Cookies are set to HttpOnly to prevent XSS attacks and steal cookie contents, which increases the security of cookies, and even so, do not store important information in cookies.

The purpose of setting HttpOnly is to prevent XSS attacks by preventing JS from reading cookies.

If you can read it in JS, what's the point of having HttpOnly?

In fact, to put it bluntly, it is to prevent javascrip{filtering}t from reading some cookies, that is, contracts and conventions, which stipulate that javascrip{filtering}t is not allowed to read cookies with HttpOnly, that's all.





Previous:ADO.NET Tutorial (5) Explain the database connection pool in detail
Next:C# Parameterized Parameters uses sp_executesql to execute sql statements
Disclaimer:
All software, programming materials or articles published by Code Farmer Network are only for learning and research purposes; The above content shall not be used for commercial or illegal purposes, otherwise, users shall bear all consequences. The information on this site comes from the Internet, and copyright disputes have nothing to do with this site. You must completely delete the above content from your computer within 24 hours of downloading. If you like the program, please support genuine software, purchase registration, and get better genuine services. If there is any infringement, please contact us by email.

Mail To:help@itsvse.com