Security issues caused by HttpOnly flag setting in the browser

Source: Internet
Author: User

Security issues caused by HttpOnly flag setting in the browser

1. Introduction

If the HttpOnly flag is set for the cookie, you can avoid JavaScript reading the cookie when XSS occurs. This is also the reason why HttpOnly is introduced. But can this method defend against attackers? The HttpOnly flag prevents the cookie from being "read". Can it prevent the cookie from being "written? The answer is no, so there is an article here, because it has been proved that the HttpOnly mark of Some browsers can be overwritten by JavaScript writing, which may be exploited by attackers to launch session fixation attacks. The topic of this article is to discuss this technology.

2. Use JavaScript to overwrite the HttpOnly flag in the cookie

When JavaScript can overwrite the HttpOnly flag in the cookie, attackers can use the HttpOnly cookie to launch the session fixation attack (

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.