Setting the secure flag in the cookies

Security team identified following flaw – Session Cookie without Secure flag set Original article on TechRepublic TechRepublic had an interesting article about the Surf Jack attack. Many people commented, some giving their own solution to the problem. However many of these solutions do not prevent the attack because they do not really address it.

Track / Trace method on web server

Symptomps: serverxyz:~ # telnet 80 Trying… Connected to Escape character is '^]'. TRACE / HTTP/1.0 HTTP/1.1 200 OK Date: Wed, 22 Aug 2012 12:17:05 GMT Server: Apache/2.0.52 (Unix) mod_ssl/2.0.52 OpenSSL/0.9.7e Connection: close Content-Type: message/http TRACE / HTTP/1.0 Connection closed by foreign host. Solution: For Apache, add the lines below to httpd.conf LoadModule…

Apache troubleshooting

Apache Error Log File All apache errors / diagnostic information other errors found during serving requests are logged to this file. Location of error log is set using ErrorLog directive. If there is any problem, you should first take a look at this file using cat, grep or any other UNIX / Linux text utilities. This apache…