You are viewing limited content. For full access, please sign in.

Discussion

Discussion

Scan file upload on public form

posted on March 29, 2021

Is there anyone who is running some type of scan on a file upload on a public facing form?  We have public facing applications that require the upload of documentation and need to ensure that these files contain nothing malicious.  

0 0
replied on April 1, 2021

You can specify the types of extensions that are allowed to be uploaded under the field properties. This could minimize the possibility of something malicious being uploaded.

  1. Under File extensions allowed, specify the three letter file extensions (e.g., .pdf, .jpg, .exe) that the field will accept. If you specify multiple file extensions, separate them with commas. If this setting is left blank, any file extensions will be accepted.


Link to more information below.

 

0 0
replied on April 2, 2021

Thank you for the reply Gilberto.  I am already limiting to only .pdf, but unfortunatly a malicious file could be disguised as a .pdf.  I am looking for a way to scan these before they pass through the dmz box to our internal network and repository.  

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.