Re: Database
by "Rajnish Bhaskar" <r.bhaskar(at)compserv.gla.ac.uk>
|
| Date: |
Tue, 08 Apr 2003 09:25:28 +0100 |
| To: |
jim barchuk <jb(at)jbarchuk.com> |
| Cc: |
hwg-languages(at)hwg.org |
| References: |
hotmail |
| |
todo: View
Thread,
Original
|
|
> 2) User uploads a file. Site stores it in a database. Site returns
> file to other users -NOT- as 'a file' as such but as a stream with
> appropriate content-type headers. The user, even one with an
> unupgraded browser, can't execute an executable that the OS can be
> tricked into thinking it is.
Er, doesn't IE/Win ignore the content-type header and make its
decision as to what to do with the file based on the exension alone,
so this wouldn't provide any extra security, or am I misunderstanding
something?
Raj.
--
Rajnish Bhaskar, r.bhaskar(at)compserv.gla.ac.uk
http://lordofthemoon.com
HWG: hwg-languages mailing list archives,
maintained by Webmasters @ IWA
This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.