Vickie Li
Dec 15, 2020

--

Thanks for reading! No, HttpOnly does not prevent or mitigate CSRF attacks. They do help mitigate XSS attacks though because attacker scripts cannot read or exfiltrate the cookies protected by HttpOnly.

--

--

Vickie Li
Vickie Li

Written by Vickie Li

Professional investigator of nerdy stuff. Hacks and secures. Creates god awful infographics. https://twitter.com/vickieli7

No responses yet