Protecting Your Cookies: HttpOnly

The following is a must-read for all webappers:

http://directwebremoting.org/blog/joe/2007/10/29/web_application_security.html