<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow json MIME type for Javascript Web Applications - Security Risks in ArcGIS JavaScript Maps SDK Questions</title>
    <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/allow-json-mime-type-for-javascript-web/m-p/358746#M33243</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Is your IIS directly exposed to the internet/ in a DMZ? if so then yes, there are some json hijacking concerns&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://security.stackexchange.com/questions/7001/how-should-web-app-developers-defend-against-json-hijacking"&gt;http://security.stackexchange.com/questions/7001/how-should-web-app-developers-defend-against-json-hijacking&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I for one (besides the obvious dont use IIS) would recommend installing your application behind a Web Application Firewall and making sure you are doing request filtering to guard against attacks and exploits&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We use mod-proxy &lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://httpd.apache.org/docs/2.2/mod/mod_proxy.html"&gt;http://httpd.apache.org/docs/2.2/mod/mod_proxy.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;and keep our tomcat server internal allowing things only as necessary.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Oct 2013 19:19:15 GMT</pubDate>
    <dc:creator>JeffPace</dc:creator>
    <dc:date>2013-10-25T19:19:15Z</dc:date>
    <item>
      <title>Allow json MIME type for Javascript Web Applications - Security Risks</title>
      <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/allow-json-mime-type-for-javascript-web/m-p/358745#M33242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;To All Javascript Developers and Web Server Administrators:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I recently downloaded an ESRI javascript web application template to a web server.&amp;nbsp; I tried to run the application using ArcGIS Online services, but it stalled on the splash page with a 404 error in Fiddler.&amp;nbsp; With a little research and past experience, I determined that it was the json MIME type not being allowed through IIS that was throwing the 404 error.&amp;nbsp; I added this MIME type and the javascript web application now works.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am wondering if I am introducing any security risks to my server by allowing this additional MIME type as it is not in the MIME type list by default?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If there is a security risk, what other configuration changes do I need to make to the server to close this security risk?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any help or information in regard to this post are greatly appreciated.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Oct 2013 17:13:44 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/allow-json-mime-type-for-javascript-web/m-p/358745#M33242</guid>
      <dc:creator>MichaelVolz</dc:creator>
      <dc:date>2013-10-24T17:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Allow json MIME type for Javascript Web Applications - Security Risks</title>
      <link>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/allow-json-mime-type-for-javascript-web/m-p/358746#M33243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Is your IIS directly exposed to the internet/ in a DMZ? if so then yes, there are some json hijacking concerns&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://security.stackexchange.com/questions/7001/how-should-web-app-developers-defend-against-json-hijacking"&gt;http://security.stackexchange.com/questions/7001/how-should-web-app-developers-defend-against-json-hijacking&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I for one (besides the obvious dont use IIS) would recommend installing your application behind a Web Application Firewall and making sure you are doing request filtering to guard against attacks and exploits&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We use mod-proxy &lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://httpd.apache.org/docs/2.2/mod/mod_proxy.html"&gt;http://httpd.apache.org/docs/2.2/mod/mod_proxy.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;and keep our tomcat server internal allowing things only as necessary.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 19:19:15 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-javascript-maps-sdk-questions/allow-json-mime-type-for-javascript-web/m-p/358746#M33243</guid>
      <dc:creator>JeffPace</dc:creator>
      <dc:date>2013-10-25T19:19:15Z</dc:date>
    </item>
  </channel>
</rss>

