Protecting Your Cookies: HttpOnly

IP address doesn’t help much either. The XSS can get the IP address and send it to the hacker, along with the cookie. Not too hard to spoof an IP address in an HTTP request

if you just want to send a command…