new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

csrf/cookie_prefixes

1 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

Cookie prefixes for CSRF token security

Cookie prefixes add security against cookie injection attacks on CSRF tokens. Two prefixes are available: __Host- prefix (stronger): - Cannot be overwritten from subdomains - Cannot have Domain attribute - Must have path of '/' - Must be marked as Secure (only sent over HTTPS) - Example: Set-Cookie: __Host-token=RANDOM; path=/; Secure - Prevents attackers on sibling subdomains or via DNS takeover from injecting matching cookies - Preferred in most cases __Secure- prefix (weaker alternative): - Can have Domain attributes - Can be overwritten by subdomains - Can have Path other than '/' - Use only if authenticated users need to visit different (sub-)domains - Prefer __Host- prefix instead when possible Both prefixes are supported by all major browsers.

Give your agent this brain