← Web Basics

Cookies, Sessions & Headers

Set-Cookie: session=...; HttpOnly; Secure; SameSite=Lax. HttpOnly blocks JS theft (anti-XSS), Secure forces HTTPS, SameSite blunts CSRF. Their absence is often the finding.

Security headers: HSTS, Content-Security-Policy (anti-XSS), X-Content-Type-Options: nosniff, X-Frame-Options (anti-clickjacking).