This article describes the method to block uploading of email attachements in webmail. This method uses the HTTP Request Custom Header option in Application Firewall Objects. HTTP Request Custom Header field allows users to configure HTTP request headers and their respective values for Application Firewall to filter traffic. For more info on HTTP Headers refer RFC 2616.
The method we use here is the HTTP Request header "Content-Disposition". The Content-Disposition header field contains the disposition-type and disposition-parm (parameter). The following screen-capture shows the wireshark capture of a webmail attachment upload in gmail.com.
NOTE: Although the solution described here has been tested, there is a possibility that it may affect traffic other than webmail. Client DPI-SSL required, if using HTTPS.
Here's how to block the upload of email attachements in webmail:
