Technical Tip: Masking sensitive application information without back-end modification
| Description | This article describes how to mask misconfigured sensitive information in the HTML body without modifying the back-end server using FortiWeb. Examples are: application used, application version, internal file path, etc. |
| Scope | FortiWeb. |
| Solution | An application on the back-end server may contain sensitive data (in this case, an application version and file path will be used as an example):
In this example, there are 2 type of elements that contain sensitive data: A test string on the HTML body and the path of the file within the HTML body. Follow these steps to mask both elements from the FortiWeb:
Test the results by checking the body of the web application and by trying to reach the file previously disclosed.
Related documents: |








