Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Disable browser file extension sniff #1898

Closed
0polar opened this issue Feb 14, 2019 · 1 comment
Closed

Disable browser file extension sniff #1898

0polar opened this issue Feb 14, 2019 · 1 comment

Comments

@0polar
Copy link
Contributor

0polar commented Feb 14, 2019

Add X-Content-Type-Options: nosniff to HTTP response headers.

Reason: someone posts GIF images in ZeroMe but named as .jpeg
I think this is a potential vulnerability.

0polar added a commit to 0polar/ZeroShift that referenced this issue Feb 14, 2019
@0polar
Copy link
Contributor Author

0polar commented Feb 15, 2019

Emm, this option not works for images and breaks current ZeroNet.

I will reopen this issue when available.

@0polar 0polar closed this as completed Feb 15, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant