Check · Browser protection · default severity high
Cookie hygiene
What Kavach checks
Session cookies should carry HttpOnly, Secure and SameSite flags.
Why it matters
HttpOnly stops JavaScript (and thus XSS) from reading the cookie; Secure keeps it off plain http; SameSite blunts CSRF. Missing flags are the most common route to stolen sessions.
How an attacker uses it
- A single XSS hole lets attacker run JavaScript on your page.
- Without HttpOnly, that script reads document.cookie directly.
- The session cookie is shipped to the attacker's server.
- They paste it into their browser and are logged in as the user.
How to fix it
Set every session cookie with: HttpOnly; Secure; SameSite=Lax
Stack-specific fixes: nginx · Apache · Caddy · Express / Node · Cloudflare
Limitations
This is a read-only observation of publicly reachable configuration at scan time. It can produce false positives/negatives (caching layers, geo-specific responses, bot defences) and does not test application logic or authenticated areas. Rule version 1.