Changes

Jump to: navigation, search

WebAppSec/Secure Coding Guidelines

7 bytes removed, 17:26, 2 February 2011
Uploads
*Use a new filename to store the file on the OS. Do not use any user controlled text for this filename or for the temporary filename.
*Store all user uploaded files on a separate domain (e.g. mozillafiles.net vs mozilla.org). Archives contents should be analyzed for malicious content (anti-malware, static analysis, etc)
'''Public Serving of Uploaded Content'''
Confirm
491
edits

Navigation menu