Internet Explorer accept cookies warning disabled

Risk Level: Low risk vulnerability  Low

Check or Attack Name: IE accept cookies

Platforms: Internet Explorer
Description:

The web browser does not display a warning before accepting a cookie from a remote site. Web sites frequently store a small file or cookie on your computer to provide customization features or to recognize you when you return. This file is usually stored in a non-secure manner and may be accessible to others.

Remedy:

Depending on your version, select one of the following choices in Internet Explorer:

  • In Internet Explorer 3.x, from the Options dialog box, go to Advanced and enable Warn Before Accepting a Cookie.

    1. Open Internet Explorer 3.x.
    2. From the View menu, select Options.
    3. Click the Advanced tab.
    4. Locate the feature and set it to the recommended value.
    5. Click OK to apply the changes.

  • In Internet Explorer 4.x, from the Internet Options dialog box, go to Advanced and disable Always accept cookies.

    1. Open Internet Explorer 4.x.
    2. From the View menu, select Internet Options.
    3. Click the Advanced tab.
    4. Locate the advanced feature and set it to the recommended value.
    5. Click OK to apply the changes.

  • In Internet Explorer 5.x, from the Internet Options dialog box, go to Security and disable Allow cookies that are stored on your computer or disable Allow per-session cookies (not stored).

    1. Open Internet Explorer 5.x.
    2. From the Tools menu, select Internet Options.
    3. Click the Security tab, and then click Custom Level.
    4. Locate the advanced feature and set it to the recommended value.
    5. Click OK to apply the changes.

For more information on cookies, see Internet Explorer topic "Control your cookie intake" at http://www.microsoft.com/ie/win31/?/ie/win31/ie40/cookie.htm.

References:

Microsoft Internet Explorer Information, Control your cookie intake, http://www.microsoft.com/windows/ie/win31/?/ie/win31/ie40/cookie.htm


X-Force Logo
Know Your Risks