Mozilla will support http-only cookies

A patch for [Bug 178993] MSIE-extension: HttpOnly cookie attribute for cross-site scripting vulnerability prevention has just been committed to mozilla’s CVS. It is not yet approved for inclusion in 1.8-branch, but trunk will have it since now.

This will help to solve some of XSS-vulnerabilities related problems

update: the patch was removed from tree, for now, but looks like it will be back soon, after passing several bureaucratic procedures

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • DZone
  • FriendFeed
  • Reddit
  • Tumblr
  • Twitter

Leave a Reply

 

 

 

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

blog comments powered by Disqus