mardi 16 octobre 2018

How secure is web page that has text mime type and contains _any_ user input

I have a web server that returns content based on user input. I want to return the content with Content-Type: text/text; but I'm not sure how secure is it.

I did a test with Content-Type: text/text; and the browser just displays the content(doesn't interpret it at all) but maybe is a way to trick the it, I'm not a security expert.

thanks




Aucun commentaire:

Enregistrer un commentaire