Web Security Fundamentals: Host-Only Cookies and Domain Scope
Master cookie scope and the Domain directive to prevent cross-subdomain leaks and implement secure-by-default session management in your web applications.
-
💬
مدرب ذكاء اصطناعي
اسأل عن أي درس واحصل على إجابة واضحة فورًا، في أي وقت. -
🕐
ابدأ في أي وقت
بلا جداول أو مواعيد نهائية — تعلّم بوتيرتك، وقتما يناسبك. -
🌐
بالعربية
الدروس والمهام والشهادة — كل ذلك بلغتك بالكامل.
حول هذه الدورة
Every web application relies on cookies for session management, but misconfigured cookie domains can expose sensitive user data to subdomain hijacking. Understanding the subtle distinction between host-only cookies and domain-scoped cookies is critical for securing modern web platforms.
This course provides a clear, text-based guide to managing cookie scope and security. You will transition from basic cookie usage to implementing precise domain restrictions, ensuring that your session identifiers and sensitive tokens remain strictly where they belong.
What you'll learn:
- Understand the core differences between host-only cookies and domain-scoped cookies
- Configure the Domain directive correctly to control access across subdomains
- Implement modern cookie attributes like Secure, HttpOnly, and SameSite for defense-in-depth
- Analyze how modern browsers handle cookie partitioning and state restrictions
- Practice identifying and fixing common cookie configuration vulnerabilities through written scenarios
- Design secure-by-default cookie strategies for multi-tenant and single-domain applications
The course begins with foundational concepts of HTTP state management before diving deep into cookie attributes, domain wildcard behaviors, and modern browser security policies. You will read through detailed architectural explanations and analyze real-world configuration examples to solidify your understanding.
This course is designed for beginner web developers, security enthusiasts, and systems administrators who want to build a solid foundation in web application security. No prior security experience is required, though a basic familiarity with how HTTP requests work is helpful.
Start reading today to secure your web applications against subdomain cookie leaks.
ما الذي ستحصل عليه
-
📜
شهادة إتمام
أضفها إلى ملفك على LinkedIn -
💬
مدرّس AI شخصي
عالق في دورة؟ اسأل مدرّسك المدمج أي شيء، في أي وقت. -
🎧
النسخة الصوتية مضمَّنة
تعلَّم أثناء تنقُّلك — دون شاشة -
♾️
وصول مدى الحياة
عُد متى شئت، بلا انتهاء -
📱
الهاتف أو الكمبيوتر
يعمل في أي مكان وعلى أي جهاز -
💸
استرداد خلال 14 يومًا
دون أسئلة -
⚡
قصير ومركَّز
2 ساعة 30 دقيقة من المحتوى التطبيقي
المراجعات
لا توجد مراجعات بعد — كن أول من يشارك تجربته.
المتعلمون أخذوا أيضًا
🔥 رائج
🎓 بشهادة
دليل عملي للامتثال لـ MLPS 2.0
شهادة
تطبيق عملي
QR 180
→
🔥 رائج
🎓 بشهادة
أساسيات هندسة الأمن السيبراني للشهادات
شهادة
تطبيق عملي
QR 180
→
💼 جاهز لسوق العمل
🎓 بشهادة
الإدارة والحوكمة العملية للأمن السيبراني
شهادة
تطبيق عملي
QR 180
→
🔥 رائج
🎓 بشهادة
اختبار اختراق الويب للمبتدئين: حقن SQL واكتشاف الثغرات
شهادة
تطبيق عملي
QR 180
→
الأسئلة الشائعة
ما الذي أحتاجه لأخذ هذه الدورة؟ +
يكفي هاتف أو كمبيوتر متصل بالإنترنت. بدون تثبيتات أو أجهزة خاصة.
كيف يمكنني الدفع؟ +
بالبطاقة عبر Stripe. لا نخزن بيانات البطاقة — يتولى Stripe ذلك بأمان.
هل يمكنني استرداد المال؟ +
نعم — استرداد كامل خلال 14 يومًا، دون أسئلة.
إلى متى يستمر وصولي؟ +
إلى الأبد. بمجرد الشراء، الدورة لك تعود إليها متى شئت.
هل سأحصل على شهادة؟ +
نعم. عند الإتمام ستحصل على شهادة يمكنك إضافتها إلى ملفك في LinkedIn.
مصمَّم للعاملين في
التقنية
التصميم
المالية
التسويق
الرعاية الصحية
التعليم
الضيافة
التصنيع
×2
اشحن مرة واحدة وادفع النصف
أضف QR 360 واحصل على 200 رصيد، بحيث تكلف كل دورة حوالي QR 45.00. لا تنتهي صلاحية الأرصدة أبداً.
QR 360
200 رصيد
QR 45.00 / دورة
أفضل قيمة
QR 900
550 رصيد
QR 40.91 / دورة
QR 1,800
1200 رصيد
QR 37.50 / دورة
الرصيد يصلح لأي دورة ولا ينتهي.