It is usually considered the responsibility of the administrators running sites where users can post to disallow the posting of such malicious code.Cookies are not directly visible to client-side programs such as JavaScript if they have been sent with the HttpOnly flag.