For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Parveez_70209's avatar
Parveez_70209
Icon for Nimbostratus rankNimbostratus
Aug 09, 2014

Vulnerabilty "web server allows MIME sniffing"

Hi Team,

 

How to mitigate the Vulnerability using Irule or by using any modifications related to HTTP Profiles or HTTP Responses.

 

web server allows MIME sniffing

 

Regards PZ

 

3 Replies

  • Will this Irule will help me into this ?

     

    when HTTP_RESPONSE { HTTP::header X-Content-Type-Options nosniff }

     

    Thanks and Regards Parveez

     

  • Hi,

     

    this irule will help you, but this header is not to be supported by old browsers (for ex. IE6, IE7).

     

  • I think you need;

    when HTTP_RESPONSE { HTTP::header insert X-Content-Type-Options "nosniff" }
    

    Given that the older browsers don't do MIME sniffing, the iRule should remove the alert from your next scan.