Homestyx hydra

R1:6ce4044bfa85

Lock MIME type configuration

Summary:
Ref T6755. This mitigates an attack where you:

- compromise an administrative account;
- configure "text/plain" as an "image" MIME type; and
- create a new macro sourced from a sensitive resource which is locally accessible over HTTP GET, using DNS rebinding.

You can then view the content of the resource in Files. By preventing the compromised account from reconfiguring the MIME types, the server will instead destroy the response and prevent the attacker from…
Repository: R1 hydra
Commit Date: Mar 25 2015