Forum Discussion

John_31769's avatar
John_31769
Icon for Nimbostratus rankNimbostratus
Mar 11, 2011

Set APM Cookies to HttpOnly

During an internal PEN test of our APM implementation, our Security group was able to inject some Java script and steal the 2 APM cookies MRHSession and Last_MRHSession. We think we could prevent this...