
Web Application Session Cookies Flag Misconfiguration Detection Scanner
Web Application Session Cookies Flag Misconfiguration Scanner
Short Info
Level
Medium
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
15 seconds
Time Interval
1 month 17 days
Scan only one
Domain, IPv4, Subdomain
Toolbox
Examines cookies set by HTTP services. Reports any session cookies set without the httponly flag. Reports any session cookies set over SSL without the secure flag. If http-enum.nse is also run, any interesting paths found by it will be checked in addition to the root.