ethical-hacker video for when performing a penetration test, how would you check if a web application's session cookies are not set with the 'HttpOnly' flag?
When performing a penetration test, how would you check if a web application's session cookies are not set with the 'HttpOnly' flag?