NShiftKey-Rule-Guide logo NShiftKey-Rule-Guide

1. Vulnerability Description

[ picture 1. vulnerability example ]

2. How to check vulnerability

3. Vulnerability Countermeasure

Encryption over SSL

Generate Secure Session ID

How to set HTTP Only

<?xml version=""1.0"" encoding=""UTF-8"">
<Context path=""/myWebApplicationPath"" useHttpOnly=""true"">
Cookie cookie = getMyCookie(""myCookieName"");
cookie.setHttpOnly(true);
<session-config>
	<cookie-config>
		<http-only>true</http-only>
	</cookie-config>
</session-config>
session.cookie_httponly = True

Enable Session Timeout and Session ID Playback.