Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Re: Content monitorting in Application Security

Re: Content monitorting in Application Security

From: Ivan Ristic <ivanr_at_webkreator.com>
Date: Mon, 10 Jan 2005 16:16:42 +0000

Ofer Shezaf wrote:
>
> Do you think that matching extension and content type header would be
> enough? If no, are you aware of any technology to determine a file type
> according to its content?

   No. The extension and the content type are provided by the client,
   therefore they cannot be trusted. You have to look into the file
   to verify it.

-- 
Ivan Ristic (http://www.modsecurity.org)
Received on Jan 10 2005
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]