Session Cookie without HttpOnly flag set
apache, javascript, php, security
Solution
You can either change settings in php.ini, or via `ini_set()` calls to change `session.cookie_secure` and `session.cookie_httponly` values to `true`.
Alternately, you can use `session_set_cookie_params()` before starting your session to get the effect you are looking for.
https://www.php.net/manual/en/function.session-set-cookie-params.php
Problem
I have joust built a website with a login system. After I've just got ready I have scanned it with Acunetix, but I got the following message: Session Cookie without HttpOnly flag set Session Cookie without Secure flag set (i guess this is only if I have SSL connection) So my question would be, that how can I set HttpOnly flag for all my Session data? I'm just using sessions when I log in the users. I'm giving them a session with their userID number and than I'm getting data using that userID. Is there any simple way that I can set ALL of the session HTTPOnly and secure them, so noone can touch them?