Cookies without Secure

Cookies without Secure in C#

Description

A cookie without Secure can be sent over HTTP and exposed to an attacker observing the network.

Potential impact

  • A stolen session or authentication cookie can lead to account takeover.

Remediation

Set CookieOptions.Secure = true or use CookieSecurePolicy.Always for sensitive cookies.

Examples

Before

csharp
response.Cookies.Append("sid", value);

After

csharp
response.Cookies.Append("sid", value, new CookieOptions { Secure = true });

Explanation:

  • Before: Without Secure, the cookie may be sent over plaintext HTTP.
  • After: Enable CookieOptions.Secure or CookieSecurePolicy.Always for sensitive cookies.

References