2021-06-03 09:05:38 +02:00
|
|
|
=== on 12 Dec 2014, 20:58:33 Sébastien Gioria wrote:
|
2021-06-02 20:44:38 +02:00
|
|
|
This rule must apply on Session cookie but not on all cookie. SomeTime it's not a problem to send cookie on HTTP channel
|
|
|
|
|
2021-06-03 09:05:38 +02:00
|
|
|
=== on 15 Dec 2014, 10:24:32 Freddy Mallet wrote:
|
2021-06-02 20:44:38 +02:00
|
|
|
I see your point [~sebastien.gioria] but for the time being we don't see anyway to know exactly what is the type of cookie.
|
|
|
|
|
2021-06-03 09:05:38 +02:00
|
|
|
=== on 2 Jun 2015, 09:25:27 Sébastien Gioria wrote:
|
2021-06-02 20:44:38 +02:00
|
|
|
I could be at OWASP-top10-A6 and OWASP-Top10-A2
|
|
|
|
|
|
|
|
|
|
|
|
|
2021-06-03 09:05:38 +02:00
|
|
|
=== on 3 Jun 2015, 20:35:51 Ann Campbell wrote:
|
2021-06-02 20:44:38 +02:00
|
|
|
Thanks [~sebastien.gioria]. A6 was already listed, but I've added A2.
|
|
|
|
|