Quantcast
Channel: All Forums
Viewing all articles
Browse latest Browse all 27852

Set HTTPOnlyCookies IIS 7.5

$
0
0

 I have been here: http://forums.iis.net/p/1168473/1946312.aspx

 http://www1.ccny.cuny.edu/facultystaff/it/security/upload/CIS_Microsoft_IIS7_Benchmark_v1-2-0.pdf (search HTTPOnly)

This isn't working in IIS 7.5

Double checked that this is applied in web.config - it is

Looking around searching on this issue it appears that only IE respects this cookie attribute?

 In particular - the offending cookie is ASPSessionXXXXXXXXXX cookie @ morephotos.com

Is the only solution the URL Rewrite rule?

 


Viewing all articles
Browse latest Browse all 27852

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>