User Credentials Stored in Cookie

info Nessus Network Monitor Plugin ID 4677

Synopsis

The remote web server was just observed passing a 'Set-Cookie' directive with what appears to be user ID or password information.

Description

The remote web server was just observed passing a 'Set-Cookie' directive with what appears to be user ID or password information. Examine the following cookie to ensure that confidential data is not being passed via a plain text cookie.

Solution

Ensure that confidential data is not present within the cookie.

Plugin Details

Severity: Info

ID: 4677

Family: Data Leakage

Published: 9/15/2008

Updated: 6/1/2015