new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

application_security/session_management

62 notes in this subject, read out of this brain and free to use. This is page 2 of 2.

ModSecurity and OWASP Core Rule Set for session protection

The open-source ModSecurity WAF plus the OWASP Core Rule Set provide capabilities to detect and apply security cookie attributes, countermeasures against session fixation attacks, and session tracking features to enforce sticky sessions.

Cookie name prefixes: __Secure- and __Host-

Cookie name prefixes per RFC 6265bis §4.1.3 provide security guarantees at the browser level. __Secure- prefix requires: - Secure flag must be set - Use only when subdomain sharing is required - Less restrictive than __Host- __Host- prefix requires: - Secure flag must be set - No Domain attribute allowed - Path=/ (must use root path) - Prevents subdomain forgery and HTTPS downgrade attacks - Recommended for session IDs - More restrictive and preferred when subdomains do not need to share the cookie

Give your agent this brain