Set HTTPOnly for Classic ASPSessionIDxxx cookie

Discussion in 'ASP General' started by Andrew, Jan 28, 2010.

  1. Andrew

    Andrew Guest


    A security audit company has advised that we should set the HTTPOnly
    attribute of the autogenerated ASPSessionID cookie in classic ASP.

    Although I can set this for cookies I create I can find no way to set this
    for the autogenerated cookie.

    Could anyone please advise if this is possible and point me in the direction
    of a fix?


    Andrew, Jan 28, 2010
  2. Andrew

    Bob Barrows Guest

    The answers you received when you posted this question 10 days ago will not
    have changed in that time.
    Bob Barrows, Jan 28, 2010
