Forum Discussion
Bob_10976
Nimbostratus
Oct 29, 2012Sensitive Cookie Missing 'HTTPONLY' Attribute
We were recently dingged by an audit scan for "Sensitive Cookie Missing 'HTTPONLY' Attribute" not being set on several of our websites, which pretty much is spread accross several different VS in the...
hoolio
Cirrostratus
Oct 29, 2012Hi Bob,
If you can't upgrade to 11.x to use the 'HTTP::cookie httponly $cookiename enable' command, you could loop through the Set-Cookie headers and insert the httponly property:
https://devcentral.f5.com/Community/GroupDetails/tabid/1082223/aft/2164062/asg/50/Default.aspx
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects