• <tfoot id='NsMJn'></tfoot>

      <bdo id='NsMJn'></bdo><ul id='NsMJn'></ul>
    <i id='NsMJn'><tr id='NsMJn'><dt id='NsMJn'><q id='NsMJn'><span id='NsMJn'><b id='NsMJn'><form id='NsMJn'><ins id='NsMJn'></ins><ul id='NsMJn'></ul><sub id='NsMJn'></sub></form><legend id='NsMJn'></legend><bdo id='NsMJn'><pre id='NsMJn'><center id='NsMJn'></center></pre></bdo></b><th id='NsMJn'></th></span></q></dt></tr></i><div id='NsMJn'><tfoot id='NsMJn'></tfoot><dl id='NsMJn'><fieldset id='NsMJn'></fieldset></dl></div>

    1. <small id='NsMJn'></small><noframes id='NsMJn'>

        <legend id='NsMJn'><style id='NsMJn'><dir id='NsMJn'><q id='NsMJn'></q></dir></style></legend>

        什么是“X-Content-Type-Options=nosniff"?

        时间:2023-08-02

            <bdo id='VpMqF'></bdo><ul id='VpMqF'></ul>

            <i id='VpMqF'><tr id='VpMqF'><dt id='VpMqF'><q id='VpMqF'><span id='VpMqF'><b id='VpMqF'><form id='VpMqF'><ins id='VpMqF'></ins><ul id='VpMqF'></ul><sub id='VpMqF'></sub></form><legend id='VpMqF'></legend><bdo id='VpMqF'><pre id='VpMqF'><center id='VpMqF'></center></pre></bdo></b><th id='VpMqF'></th></span></q></dt></tr></i><div id='VpMqF'><tfoot id='VpMqF'></tfoot><dl id='VpMqF'><fieldset id='VpMqF'></fieldset></dl></div>

            <small id='VpMqF'></small><noframes id='VpMqF'>

              <tfoot id='VpMqF'></tfoot>
                1. <legend id='VpMqF'><style id='VpMqF'><dir id='VpMqF'><q id='VpMqF'></q></dir></style></legend>

                    <tbody id='VpMqF'></tbody>
                2. 本文介绍了什么是“X-Content-Type-Options=nosniff"?的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着跟版网的小编来一起学习吧!

                  问题描述

                  我正在使用 OWASP ZAP 在我的本地主机上进行一些渗透测试,它一直报告此消息:

                  I am doing some penetration testing on my localhost with OWASP ZAP, and it keeps reporting this message:

                  Anti-MIME-Sniffing 标头 X-Content-Type-Options 未设置为'nosniff'

                  The Anti-MIME-Sniffing header X-Content-Type-Options was not set to 'nosniff'

                  此检查特定于 Internet Explorer 8 和 Google Chrome.确保每个页面都设置了 Content-Type 标头和如果 Content-Type 标头未知,则为 X-CONTENT-TYPE-OPTIONS

                  This check is specific to Internet Explorer 8 and Google Chrome. Ensure each page sets a Content-Type header and the X-CONTENT-TYPE-OPTIONS if the Content-Type header is unknown

                  我不知道这意味着什么,我在网上找不到任何东西.我已经尝试添加:

                  I have no idea what this means, and I couldn't find anything online. I have tried adding:

                  <meta content="text/html; charset=UTF-8; X-Content-Type-Options=nosniff" http-equiv="Content-Type" />
                  

                  但我仍然收到警报.

                  设置参数的正确方法是什么?

                  What is the correct way of setting the parameter?

                  推荐答案

                  它可以防止浏览器进行 MIME 类型的嗅探.大多数浏览器现在都尊重此标头,包括 Chrome/Chromium、Edge、IE >= 8.0、Firefox >= 50 和 Opera >= 13.请参阅:

                  It prevents the browser from doing MIME-type sniffing. Most browsers are now respecting this header, including Chrome/Chromium, Edge, IE >= 8.0, Firefox >= 50 and Opera >= 13. See :

                  https://blogs.msdn.com/b/ie/archive/2008/09/02/ie8-security-part-vi-beta-2-update.aspx?Redirected=true

                  发送带有值的新 X-Content-Type-Options 响应标头nosniff 将阻止 Internet Explorer MIME 嗅探响应远离声明的内容类型.

                  Sending the new X-Content-Type-Options response header with the value nosniff will prevent Internet Explorer from MIME-sniffing a response away from the declared content-type.

                  哦,那是 HTTP 标头,而不是 HTML 元标记选项.

                  Oh and, that's an HTTP header, not a HTML meta tag option.

                  另请参阅:http://msdn.microsoft.com/en-us/library/ie/gg622941(v=vs.85).aspx

                  这篇关于什么是“X-Content-Type-Options=nosniff"?的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持跟版网!

                  上一篇:通过整数在 Azure Functions 中 SQL 查询 DocumentDB 不起作用 下一篇:使用 JavaScript 添加自定义 HTTP 标头

                  相关文章

                  <legend id='jSyTZ'><style id='jSyTZ'><dir id='jSyTZ'><q id='jSyTZ'></q></dir></style></legend>

                    <tfoot id='jSyTZ'></tfoot>

                  1. <i id='jSyTZ'><tr id='jSyTZ'><dt id='jSyTZ'><q id='jSyTZ'><span id='jSyTZ'><b id='jSyTZ'><form id='jSyTZ'><ins id='jSyTZ'></ins><ul id='jSyTZ'></ul><sub id='jSyTZ'></sub></form><legend id='jSyTZ'></legend><bdo id='jSyTZ'><pre id='jSyTZ'><center id='jSyTZ'></center></pre></bdo></b><th id='jSyTZ'></th></span></q></dt></tr></i><div id='jSyTZ'><tfoot id='jSyTZ'></tfoot><dl id='jSyTZ'><fieldset id='jSyTZ'></fieldset></dl></div>
                    • <bdo id='jSyTZ'></bdo><ul id='jSyTZ'></ul>

                      <small id='jSyTZ'></small><noframes id='jSyTZ'>