fromtheblacklagoon / portfolio

0 stars 0 forks source link

browser security learning / experimenting #10

Open fromtheblacklagoon opened 10 months ago

fromtheblacklagoon commented 10 months ago

Build toy hapi file server to experiment w/ security concerns

Content-Type / mime sniffing

Reading

https://macarthur.me/posts/trigger-cross-origin-download

https://security.stackexchange.com/questions/256357/is-mime-sniffing-still-something-to-protect-against-with-modern-browsers-with-x https://wanago.io/2022/03/14/mime-sniffing-x-content-type-options-content-type/ https://mimesniff.spec.whatwg.org/