[WEB SECURITY] Serverside Virus Scan

rajat karnwal rajatpch at yahoo.com
Fri May 2 16:24:13 EDT 2008

   I have a requirement of doing server side virus
scan and also needs to check the that file extension
are not spoofed for the files uploaded. Max upload
file size allowed will be few MB. Application is in
   I know there are two approaches to acheive this
First Approach) Integrate virus scan with the
application and do in memory scan

Second Approach)  Download file into some secured area
and then do virus scan. If file contains virus
qurantine it.
   What I am not sure is which approach is the
preffered approach. What are the pros and cons of
  Any help will be appreciated
Rajat Karnwal

