WebApp Sec mailing list archives

[Web Security] File Upload Virus Scanning


From: 0x4150 <0x4150 () gmail com>
Date: Fri, 9 Jul 2010 13:13:13 -0500

All,

I am reviewing Java EE web application which allows uploads of various
file types, stores them in a directory, and then offers the same files
to other users for download. The files could be images (jpg, gif,
png), documents (doc, docx, xls, pdf), or text files(txt, csv).

My question is regarding virus scanning of these uploaded files. With
vulnerabilities being reported in formats like PDF, I would like to
protect the users and infrastructure as much as possible.

Are there any best practices for this?

What products (commercial or free) should I evaluate for this process?

Thanks in advance for any insight!



This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now! 
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------


Current thread: