Protecting Your Cookies: HttpOnly

Now if only your friend would listen to the white list don’t black list suggestion he could, with some consideration, avoid all XSS attacks.