<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Protecting Cookie from XSS using HttpOnly and Secure flag</title>
	<atom:link href="http://www.ilmuhacking.com/web-security/protecting-cookie-from-xss-using-httponly-secure-flag/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ilmuhacking.com/web-security/protecting-cookie-from-xss-using-httponly-secure-flag/</link>
	<description>Hackingology, Computer Security Blog</description>
	<lastBuildDate>Sun, 29 Aug 2010 01:40:08 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: eric</title>
		<link>http://www.ilmuhacking.com/web-security/protecting-cookie-from-xss-using-httponly-secure-flag/comment-page-1/#comment-634</link>
		<dc:creator>eric</dc:creator>
		<pubDate>Wed, 12 May 2010 08:20:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.ilmuhacking.com/?p=1224#comment-634</guid>
		<description>mas rizki, klo udah dapat cookie facebook kira2 diapain ya supaya bisa dipakai buat login, soalx cookie yang terlihat pada saat logoff facebook dan pada saat aktif kok beda ya. klo beda pake apa sih untuk decryptx. Mohon pencerahanx. terima kasih.</description>
		<content:encoded><![CDATA[<p>mas rizki, klo udah dapat cookie facebook kira2 diapain ya supaya bisa dipakai buat login, soalx cookie yang terlihat pada saat logoff facebook dan pada saat aktif kok beda ya. klo beda pake apa sih untuk decryptx. Mohon pencerahanx. terima kasih.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: isnawan</title>
		<link>http://www.ilmuhacking.com/web-security/protecting-cookie-from-xss-using-httponly-secure-flag/comment-page-1/#comment-505</link>
		<dc:creator>isnawan</dc:creator>
		<pubDate>Mon, 18 Jan 2010 12:28:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.ilmuhacking.com/?p=1224#comment-505</guid>
		<description>&lt;a href=&quot;#comment-221&quot; rel=&quot;nofollow&quot;&gt;@Rizki Wicaksono&lt;/a&gt; 
mas rizki, ajarin cara mencuri cookie donk. contohny mksdny.udah cba cari2 gk berhasil  oi...biasanya website gk cuma ngasih satu cookie ya? ..makasih...</description>
		<content:encoded><![CDATA[<p><a href="#comment-221" rel="nofollow">@Rizki Wicaksono</a><br />
mas rizki, ajarin cara mencuri cookie donk. contohny mksdny.udah cba cari2 gk berhasil  oi&#8230;biasanya website gk cuma ngasih satu cookie ya? ..makasih&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HERLoct_HENT</title>
		<link>http://www.ilmuhacking.com/web-security/protecting-cookie-from-xss-using-httponly-secure-flag/comment-page-1/#comment-496</link>
		<dc:creator>HERLoct_HENT</dc:creator>
		<pubDate>Sun, 10 Jan 2010 14:11:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.ilmuhacking.com/?p=1224#comment-496</guid>
		<description>thanks mas, infonya

hmm... kudu cari httpOnly di J2EE juga nih kayanya :(</description>
		<content:encoded><![CDATA[<p>thanks mas, infonya</p>
<p>hmm&#8230; kudu cari httpOnly di J2EE juga nih kayanya <img src='http://www.ilmuhacking.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ozt</title>
		<link>http://www.ilmuhacking.com/web-security/protecting-cookie-from-xss-using-httponly-secure-flag/comment-page-1/#comment-445</link>
		<dc:creator>ozt</dc:creator>
		<pubDate>Tue, 17 Nov 2009 20:00:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.ilmuhacking.com/?p=1224#comment-445</guid>
		<description>bos, untuk cookie dengan flag httpOnly, otomatis pada aplikasi ajax ga jalan dunk?</description>
		<content:encoded><![CDATA[<p>bos, untuk cookie dengan flag httpOnly, otomatis pada aplikasi ajax ga jalan dunk?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 0nt4</title>
		<link>http://www.ilmuhacking.com/web-security/protecting-cookie-from-xss-using-httponly-secure-flag/comment-page-1/#comment-288</link>
		<dc:creator>0nt4</dc:creator>
		<pubDate>Sat, 13 Jun 2009 19:43:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.ilmuhacking.com/?p=1224#comment-288</guid>
		<description>mas klo ntu scrip kta taro dmana byar korban bsa kena jerat,..</description>
		<content:encoded><![CDATA[<p>mas klo ntu scrip kta taro dmana byar korban bsa kena jerat,..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Binus Hacker &#187; Hacking Email Telkom.net dan Plasa.com</title>
		<link>http://www.ilmuhacking.com/web-security/protecting-cookie-from-xss-using-httponly-secure-flag/comment-page-1/#comment-278</link>
		<dc:creator>Binus Hacker &#187; Hacking Email Telkom.net dan Plasa.com</dc:creator>
		<pubDate>Mon, 01 Jun 2009 11:10:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.ilmuhacking.com/?p=1224#comment-278</guid>
		<description>[...] dalam bentuk cookie, apalagi bila cookie tersebut diamankan dengan bit secure atau httponly (baca: protecting cookie with httponly ). Kemungkinan serangan yang bisa dilancarkan untuk mencuri cookie adalah dengan XSS attack dan [...]</description>
		<content:encoded><![CDATA[<p>[...] dalam bentuk cookie, apalagi bila cookie tersebut diamankan dengan bit secure atau httponly (baca: protecting cookie with httponly ). Kemungkinan serangan yang bisa dilancarkan untuk mencuri cookie adalah dengan XSS attack dan [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hacking Email Telkom.net dan Plasa.com &#124; Web Security &#124; IlmuHacking.com</title>
		<link>http://www.ilmuhacking.com/web-security/protecting-cookie-from-xss-using-httponly-secure-flag/comment-page-1/#comment-235</link>
		<dc:creator>Hacking Email Telkom.net dan Plasa.com &#124; Web Security &#124; IlmuHacking.com</dc:creator>
		<pubDate>Wed, 29 Apr 2009 13:56:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.ilmuhacking.com/?p=1224#comment-235</guid>
		<description>[...] dalam bentuk cookie, apalagi bila cookie tersebut diamankan dengan bit secure atau httponly (baca: protecting cookie with httponly ). Kemungkinan serangan yang bisa dilancarkan untuk mencuri cookie adalah dengan XSS attack dan [...]</description>
		<content:encoded><![CDATA[<p>[...] dalam bentuk cookie, apalagi bila cookie tersebut diamankan dengan bit secure atau httponly (baca: protecting cookie with httponly ). Kemungkinan serangan yang bisa dilancarkan untuk mencuri cookie adalah dengan XSS attack dan [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rizki Wicaksono</title>
		<link>http://www.ilmuhacking.com/web-security/protecting-cookie-from-xss-using-httponly-secure-flag/comment-page-1/#comment-221</link>
		<dc:creator>Rizki Wicaksono</dc:creator>
		<pubDate>Mon, 20 Apr 2009 06:37:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.ilmuhacking.com/?p=1224#comment-221</guid>
		<description>&lt;a href=&quot;#comment-220&quot; rel=&quot;nofollow&quot;&gt;@johan&lt;/a&gt; 
itu saya pakai addon Firefox &quot;Live HTTP Header&quot;</description>
		<content:encoded><![CDATA[<p><a href="#comment-220" rel="nofollow">@johan</a><br />
itu saya pakai addon Firefox &#8220;Live HTTP Header&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: johan</title>
		<link>http://www.ilmuhacking.com/web-security/protecting-cookie-from-xss-using-httponly-secure-flag/comment-page-1/#comment-220</link>
		<dc:creator>johan</dc:creator>
		<pubDate>Mon, 20 Apr 2009 05:11:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.ilmuhacking.com/?p=1224#comment-220</guid>
		<description>nanya donk.
gimana sih cara nya liat log seperti ini ?
http://localhost/testhttponly/testcookie.php
 
GET /testhttponly/testcookie.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.8) Gecko/2009032609 Firefox/3.0.8 GTB5 ImageShackToolbar/5.0.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Set-Cookie: PHPSESSID=90c2de0ac88e251476b3518ac92513a1; path=/; secure</description>
		<content:encoded><![CDATA[<p>nanya donk.<br />
gimana sih cara nya liat log seperti ini ?<br />
<a href="http://localhost/testhttponly/testcookie.php" rel="nofollow">http://localhost/testhttponly/testcookie.php</a></p>
<p>GET /testhttponly/testcookie.php HTTP/1.1<br />
Host: localhost<br />
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.8) Gecko/2009032609 Firefox/3.0.8 GTB5 ImageShackToolbar/5.0.0<br />
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8<br />
Accept-Language: en-us,en;q=0.5<br />
Accept-Encoding: gzip,deflate<br />
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7<br />
Keep-Alive: 300<br />
Connection: keep-alive<br />
Set-Cookie: PHPSESSID=90c2de0ac88e251476b3518ac92513a1; path=/; secure</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rizki Wicaksono</title>
		<link>http://www.ilmuhacking.com/web-security/protecting-cookie-from-xss-using-httponly-secure-flag/comment-page-1/#comment-208</link>
		<dc:creator>Rizki Wicaksono</dc:creator>
		<pubDate>Tue, 14 Apr 2009 12:43:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.ilmuhacking.com/?p=1224#comment-208</guid>
		<description>&lt;a href=&quot;#comment-207&quot; rel=&quot;nofollow&quot;&gt;@MISRINA&lt;/a&gt; 
itu artinya browsermu tidak menerima cookie, bukan di-&quot;hacker&quot;...</description>
		<content:encoded><![CDATA[<p><a href="#comment-207" rel="nofollow">@MISRINA</a><br />
itu artinya browsermu tidak menerima cookie, bukan di-&#8221;hacker&#8221;&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
