SCANTIDE ONLINE
Scantide Online Guide

What Public Cookie Attributes Can Tell You About a Website

Cookies visible to an external client can reveal session handling, third-party integrations and whether important attributes such as Secure and SameSite are present.

Technical guideUpdated 25 September 2026Scantide Online
Short answer: Cookies visible to an external client can reveal session handling, third-party integrations and whether important attributes such as Secure and SameSite are present.

Cookies are application state

They can maintain sessions, preferences, analytics identifiers and consent choices. Their significance depends on what the cookie represents.

Attributes show part of the security posture

Secure, HttpOnly and SameSite can reduce specific risks when configured appropriately, but no single flag makes a cookie safe.

Third-party behavior matters

Cookies can be associated with external analytics or embedded services, expanding the privacy context beyond the primary domain.

Online provides public evidence

Scantide Online can include cookie context in the external domain assessment, while Observe can provide a more immediate browser-side view for the current page.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: SSL and TLS Scanner for Public Websites

Scantide Online reviews public DNS, mail-security records, HTTP/HTTPS behavior, TLS, security headers, cookies, infrastructure and CVE-related context to provide a readable external assessment of a domain.

Current Scantide source: Public Server Security Assessment

Use Scantide Online to review public hosts, HTTPS, headers, DNS and infrastructure evidence for a readable first-pass public server security assessment.

Current Scantide source: Website Security Header Scanner

Scantide Online reviews website security headers such as HSTS, CSP, X-Frame-Options and related browser controls in the context of the public site.

Current Scantide source: External Attack Surface Assessment and Discovery

External attack surface work begins with visibility: which hosts answer, which services are exposed and which systems appear to belong to the organization.

Current Scantide source: DNS, SPF and DMARC Security Checker

Scantide Online checks public DNS and mail-security signals including SPF and DMARC as part of a broader external domain assessment.

Field experience from the archive

Historical source · JufCorp: Securing your servers, users and customers online

Also, you external DNS server needs to be secured! Have a word with your ISP or whoever is running the external DNS server and see what they've got in place.

A 0day is a security bug in the software of the server your running and they vary on how much impact they may have. The name comes from that it is day 0 of it's public release and the manufacturer, in this case Microsoft, hasn't released any patch against it leaving you vulnerable no matter what you do. Some of them are even just a nifty way of adding stuff (specific strings ) to the URL or the service the attacker wants to reach and bypassing all of the built in security by "fooling" the server. Whatever they do, keep track of when they surface and see what can be done to mitigate them.

Historical source · JufCorp: Juha Jurvanen

Currently I'm actually employed as IT Business Analyst. I still do cnsulting for external clients etc but not on a full time basis.

Historical source · JufCorp: Anyone ideas? How to disable vompatibility check in Excel 2007?

Disbling compatibiliy check when opening 2003 .xls in @Office 2007 impossible. Gah. Comp-check f##%s it up in remote app when alt pg up don't work.

Practical review checklist

Frequently asked questions

Can an external scan see every cookie?

No. Cookies can vary by page, authentication state, consent and browser behavior.

Is a cookie without HttpOnly always dangerous?

No. Some cookies need script access; sensitivity and purpose matter.

Check the evidence with Scantide Online

External domain security, privacy and infrastructure assessment. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Run Scantide OnlineMore guidesAll Scantide guides