Re: [Web Security] File Upload Virus Scanning
| Newsgroups | gmane.comp.security.websecurity,gmane.comp.security.basics,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <1843744275-1278717430-cardhu_decombobulator_blackberry.rim.net-1201926473-@bda163.bisx.prod.on.blackberry> |
Ok, agree, sensitive information requires encryption, thanks for the clarification. Sent via BlackBerry from Danux Network -----Original Message----- From: 0x4150 <[email protected]> Date: Fri, 9 Jul 2010 17:31:37 To: Danux<[email protected]>; <[email protected]>; <[email protected]>; <[email protected]> Subject: Re: [WEB SECURITY] [Web Security] File Upload Virus Scanning Danux, The transfer (up and down) will have to be HTTPS as the file contains sensitive information. > Apart from Content-type header in the response, also make sure to use > HTTP instead of HTTPS when sending the file to the end user, this way, > there is a change that another security control like IDS/IPS can catch > the file while flowing back to the end user through the network. Robert, Thanks for that awesome explanation! +1 Kudos ---------------------------------------------------------------------------- Join us on IRC: irc.freenode.net #webappsec Have a question? Search The Web Security Mailing List Archives: http://www.webappsec.org/lists/websecurity/archive/ Subscribe via RSS: http://www.webappsec.org/rss/websecurity.rss [RSS Feed] To unsubscribe email [email protected] and reply to the confirmation email Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA WASC on Twitter http://twitter.com/wascupdates