• <tfoot id='NsMJn'></tfoot>

      <bdo id='NsMJn'></bdo><ul id='NsMJn'></ul>
    <i id='NsMJn'><tr id='NsMJn'><dt id='NsMJn'><q id='NsMJn'><span id='NsMJn'><b id='NsMJn'><form id='NsMJn'><ins id='NsMJn'></ins><ul id='NsMJn'></ul><sub id='NsMJn'></sub></form><legend id='NsMJn'></legend><bdo id='NsMJn'><pre id='NsMJn'><center id='NsMJn'></center></pre></bdo></b><th id='NsMJn'></th></span></q></dt></tr></i><div id='NsMJn'><tfoot id='NsMJn'></tfoot><dl id='NsMJn'><fieldset id='NsMJn'></fieldset></dl></div>

    1. <small id='NsMJn'></small><noframes id='NsMJn'>

        <legend id='NsMJn'><style id='NsMJn'><dir id='NsMJn'><q id='NsMJn'></q></dir></style></legend>

        什么是“X-Content-Type-Options=nosniff"?

        What is quot;X-Content-Type-Options=nosniffquot;?(什么是“X-Content-Type-Options=nosniff?)

            <bdo id='VpMqF'></bdo><ul id='VpMqF'></ul>

            <i id='VpMqF'><tr id='VpMqF'><dt id='VpMqF'><q id='VpMqF'><span id='VpMqF'><b id='VpMqF'><form id='VpMqF'><ins id='VpMqF'></ins><ul id='VpMqF'></ul><sub id='VpMqF'></sub></form><legend id='VpMqF'></legend><bdo id='VpMqF'><pre id='VpMqF'><center id='VpMqF'></center></pre></bdo></b><th id='VpMqF'></th></span></q></dt></tr></i><div id='VpMqF'><tfoot id='VpMqF'></tfoot><dl id='VpMqF'><fieldset id='VpMqF'></fieldset></dl></div>

            <small id='VpMqF'></small><noframes id='VpMqF'>

              <tfoot id='VpMqF'></tfoot>
                1. <legend id='VpMqF'><style id='VpMqF'><dir id='VpMqF'><q id='VpMqF'></q></dir></style></legend>

                    <tbody id='VpMqF'></tbody>
                2. 本文介绍了什么是“X-Content-Type-Options=nosniff"?的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着跟版网的小编来一起学习吧!

                  问题描述

                  我正在使用 OWASP ZAP 在我的本地主机上进行一些渗透测试,它一直报告此消息:

                  I am doing some penetration testing on my localhost with OWASP ZAP, and it keeps reporting this message:

                  Anti-MIME-Sniffing 标头 X-Content-Type-Options 未设置为'nosniff'

                  The Anti-MIME-Sniffing header X-Content-Type-Options was not set to 'nosniff'

                  此检查特定于 Internet Explorer 8 和 Google Chrome.确保每个页面都设置了 Content-Type 标头和如果 Content-Type 标头未知,则为 X-CONTENT-TYPE-OPTIONS

                  This check is specific to Internet Explorer 8 and Google Chrome. Ensure each page sets a Content-Type header and the X-CONTENT-TYPE-OPTIONS if the Content-Type header is unknown

                  我不知道这意味着什么,我在网上找不到任何东西.我已经尝试添加:

                  I have no idea what this means, and I couldn't find anything online. I have tried adding:

                  <meta content="text/html; charset=UTF-8; X-Content-Type-Options=nosniff" http-equiv="Content-Type" />
                  

                  但我仍然收到警报.

                  设置参数的正确方法是什么?

                  What is the correct way of setting the parameter?

                  推荐答案

                  它可以防止浏览器进行 MIME 类型的嗅探.大多数浏览器现在都尊重此标头,包括 Chrome/Chromium、Edge、IE >= 8.0、Firefox >= 50 和 Opera >= 13.请参阅:

                  It prevents the browser from doing MIME-type sniffing. Most browsers are now respecting this header, including Chrome/Chromium, Edge, IE >= 8.0, Firefox >= 50 and Opera >= 13. See :

                  https://blogs.msdn.com/b/ie/archive/2008/09/02/ie8-security-part-vi-beta-2-update.aspx?Redirected=true

                  发送带有值的新 X-Content-Type-Options 响应标头nosniff 将阻止 Internet Explorer MIME 嗅探响应远离声明的内容类型.

                  Sending the new X-Content-Type-Options response header with the value nosniff will prevent Internet Explorer from MIME-sniffing a response away from the declared content-type.

                  哦,那是 HTTP 标头,而不是 HTML 元标记选项.

                  Oh and, that's an HTTP header, not a HTML meta tag option.

                  另请参阅:http://msdn.microsoft.com/en-us/library/ie/gg622941(v=vs.85).aspx

                  这篇关于什么是“X-Content-Type-Options=nosniff"?的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持跟版网!

                  本站部分内容来源互联网,如果有图片或者内容侵犯了您的权益,请联系我们,我们会在确认后第一时间进行删除!

                  相关文档推荐

                  quot;Status Code:200 OK (from ServiceWorker)quot; in Chrome Network DevTools?(“状态码:200 OK(来自 ServiceWorker)在 Chrome 网络开发工具中?)
                  How to set a header for a HTTP GET request, and trigger file download?(如何为 HTTP GET 请求设置标头并触发文件下载?)
                  Adding custom HTTP headers using JavaScript(使用 JavaScript 添加自定义 HTTP 标头)
                  SmtpJs API not working! is there any way to send emails using SMTP server with JavaScript or JQuery(SmtpJs API 不工作!有没有办法使用带有 JavaScript 或 JQuery 的 SMTP 服务器发送电子邮件)
                  Can I send email using javascript(我可以使用 javascript 发送电子邮件吗)
                  Select All the objects on canvas using Fabric.js(使用 Fabric.js 选择画布上的所有对象)
                  <legend id='jSyTZ'><style id='jSyTZ'><dir id='jSyTZ'><q id='jSyTZ'></q></dir></style></legend>

                    <tfoot id='jSyTZ'></tfoot>

                    • <i id='jSyTZ'><tr id='jSyTZ'><dt id='jSyTZ'><q id='jSyTZ'><span id='jSyTZ'><b id='jSyTZ'><form id='jSyTZ'><ins id='jSyTZ'></ins><ul id='jSyTZ'></ul><sub id='jSyTZ'></sub></form><legend id='jSyTZ'></legend><bdo id='jSyTZ'><pre id='jSyTZ'><center id='jSyTZ'></center></pre></bdo></b><th id='jSyTZ'></th></span></q></dt></tr></i><div id='jSyTZ'><tfoot id='jSyTZ'></tfoot><dl id='jSyTZ'><fieldset id='jSyTZ'></fieldset></dl></div>
                        • <bdo id='jSyTZ'></bdo><ul id='jSyTZ'></ul>

                              <tbody id='jSyTZ'></tbody>

                            <small id='jSyTZ'></small><noframes id='jSyTZ'>