Protecting Your Cookies: HttpOnly

@Emmanuel

Neat-o… does Rails have an automated script to test all the known XSS attacks on ha.ckers.com?

http://ha.ckers.org/xss.html

I wouldn’t be surprised if one or two slipped by…