Jump to content

List of Dangerous MIME types?


shadiadiph

Recommended Posts

Not sure exactly what you're doing, but I generally follow 2 rules:

 

1.  Never trust mime-types.  They can be faked.  Always go by file extensions, since they are usually what decides how a file gets handled (by Apache anyway, and on Windows... on linux it's a bit different)

 

2.  Always white list if possible.  It's easier to keep a list of what is allowed than maintain a list of what is not allowed.

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.