is illusory xss dispute obtain httponly cookies?
reading finished me start thinking, illusory an httponly cookie achieved by any form xss? jeff mentions "raises bar considerably" nonetheless creates sound doesn't totally strengthen opposing xss. aside fact browser support underline properly, hacker obtain user's cookies httponly? i can't cruise any proceed an httponly cookie send itself another site review script, seems stable confidence feature, nonetheless i'm always vacant during simply work around confidence layers. in sourroundings i work in, ie exclusively browsers aren't concern. i'm looking personally ways spin an emanate don't rest browser specific flaws.