<span id="7ztzv"></span>
<sub id="7ztzv"></sub>

<span id="7ztzv"></span><form id="7ztzv"></form>

<span id="7ztzv"></span>

        <address id="7ztzv"></address>

            Cookie Security: HTTPOnly not Set

            ABSTRACT

            程序創建了 cookie,但未能將 HttpOnly 標記設置為 true

            EXPLANATION

            Microsoft Internet Explorer 支持 HttpOnly cookie 屬性,可阻止客戶端腳本訪問 cookie。cross-site scripting 攻擊通常會訪問 cookie,以試圖竊取會話標識符或 authentication 標記。如果未啟用 HttpOnly,攻擊者就能更容易地訪問用戶 cookie。


            例 1:以下示例中的代碼創建 cookie,但沒有設置 HttpOnly 屬性。


            setcookie("emailCookie", $email, 0, "/", "www.example.com", TRUE); //Missing 7th parameter to set HttpOnly

            REFERENCES

            [1] Standards Mapping - OWASP Top 10 2004 - (OWASP 2004) A10 Insecure Configuration Management

            [2] Standards Mapping - OWASP Top 10 2010 - (OWASP 2010) A6 Security Misconfiguration

            [3] Standards Mapping - FIPS200 - (FISMA) CM

            [4] Standards Mapping - Web Application Security Consortium 24 + 2 - (WASC 24 + 2) Insufficient Authentication

            [5] Standards Mapping - Payment Card Industry Data Security Standard Version 1.1 - (PCI 1.1) Requirement 6.5.10

            [6] Amit Klein Round-up:Ways to bypass HttpOnly (and HTTP Basic auth)

            [7] setcookie() documentation The PHP Group


            Copyright 2013 Fortify Software - All rights reserved.
            (Generated from version 2013.1.1.0008 of the Fortify Secure Coding Rulepacks)
            desc.semantic.php.cookie_security_httponly_not_set

            <span id="7ztzv"></span>
            <sub id="7ztzv"></sub>

            <span id="7ztzv"></span><form id="7ztzv"></form>

            <span id="7ztzv"></span>

                  <address id="7ztzv"></address>

                      亚洲欧美在线