javascript - A invisible cookiewhy? -


i'm wanting cookies habbo.com.br site consists of _gads _utma _utmb _utmc _utmt _utmz _ga _gat browser_token session.id , ypf8827340282jdskjhfiw_928937459182jax666 when give comanto alert (document.cooki) returns me values except browser_token session.id , why?

enter image description here

enter image description here

when load webpage, web server may decide set cookie httponly. means web server, when load new pages, can read cookie, , it's inaccessible scripts in browser (including code run developer console or address bar). if can read cookie extension, not script (such alert(document.cookie), seems explanation.

this commonly done session identifying cookies (i.e., cookies contain information necessary stay logged in). reason if these, "copy" them own machine , logged in you. typically don't want these cookies accessible through scripts, relatively common place attack visitors of webpage.


Comments

Popular posts from this blog

ios - RestKit 0.20 — CoreData: error: Failed to call designated initializer on NSManagedObject class (again) -

java - Digest auth with Spring Security using javaconfig -

laravel - PDOException in Connector.php line 55: SQLSTATE[HY000] [1045] Access denied for user 'root'@'localhost' (using password: YES) -