• Sign In
  • Join

Microsoft
  • IIS
  • Home
  • Manage
  • Downloads
  • Learn
  • Reference
  • Solutions
    • Technologies
    • .NET Framework
    • ASP.NET
    • PHP
    • Windows Server
    • SQL Server
    • Web App Gallery
    • Microsoft Azure
    • Tools
    • Visual Studio
    • Visual Studio Code
    • Web Platform Installer
    • Get Help:
    • Ask a Question in our Forums
    • More Help Resources
  • Blogs
  • Forums

Home IIS.NET Forums IIS 5 & IIS 6 Classic ASP Setting HTTPONLY for CLASSIC ASP Session Cookie - URGENT HELP NEEDED... Setting HTTPONLY for CLASSIC ASP Session Cookie - URGENT HELP NEEDED...

View Complete Thread

Shortcuts

  • Active Threads
  • Unanswered Threads
  • Unresolved Threads
  • Advanced Search
    • Reply
    Shafii Shafii

    3 Posts

    Setting HTTPONLY for CLASSIC ASP Session Cookie - URGENT HELP NEEDED PLEASE!!!

    Jun 07, 2010 06:00 PM|Shafii|LINK

    Hello all,

    I'm not really sure if this should fall under the IIS.net forum, but i had a similar issue where i needed to update the Metabase.xml so it might be a similar fix.

    Basically, this is the final thing that's been flagged in a vulnerability scan and needs fixing ASAP, so any help is hugely appreciated.

    I need to know how to set HTTPONLY on the ASPSESSION cookie created by default from ASP & IIS. This is the cookie is automatically created by the server for all asp pages. The issue i had before was to do with setting the cookie as secure because this is running through https.

    If needed i can set HTTPONLY on all cookie across the site.

    Any help on how to do this would be massively appreciated.

    Thanks a lot,
    Elliott

    HTTPONLY for CLASSIC ASP Session Cookie

  • This site is managed for Microsoft by Neudesic, LLC. | © 2019 Microsoft. All rights reserved.
  • Privacy Statement
  • Terms of Use
  • Contact Us
  • Advertise with Us
  • Hosted on Microsoft Azure
  • Follow us on:
  • Twitter
  • Facebook
  • Microsoft
  • Feedback on IIS