Forum Discussion
Vulnerabilty "web server allows MIME sniffing"
Hi Team,
How to mitigate the Vulnerability using Irule or by using any modifications related to HTTP Profiles or HTTP Responses.
web server allows MIME sniffing
Regards PZ
3 Replies
- Parveez_70209
Nimbostratus
Will this Irule will help me into this ?
when HTTP_RESPONSE { HTTP::header X-Content-Type-Options nosniff }
Thanks and Regards Parveez
- Vitaliy_Savrans
Nacreous
Hi,
this irule will help you, but this header is not to be supported by old browsers (for ex. IE6, IE7).
- IheartF5_45022
Nacreous
I think you need;
when HTTP_RESPONSE { HTTP::header insert X-Content-Type-Options "nosniff" }Given that the older browsers don't do MIME sniffing, the iRule should remove the alert from your next scan.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com