About tomcat7's JSESSION acquisition is not worth solving

Tomcat7 for security, to prevent artificial modification sessionid attack, set JSESSION in the cookie to httponly=true, so that the JSESSIONID cannot be obtained by using the cookie



How to get JSESSIONID. Modify the conf/context.xml file in the tomcat directory . useHttpOnlu="false"






Guess you like

Origin http://43.154.161.224:23101/article/api/json?id=325601717&siteId=291194637