Question
How to prevent information disclusore by renaming "cookiesession1"?
Hi,
For the first HTTP/HTTPS request from a client, FortiWeb embeds a cookie in the response’s Set-Cookie: field in the HTTP header. It is named cookiesession1. you will see this cookie name (coockiesession1) if you capture a HTTP/HTTPS packet Since this is a uniqe cookie name, a disclusore happened becuase the attacker notices that there is a fortiweb appliance on the traffic of backend servers. my question is How can i rename "cookiesession1" in order to prevent information disclusore from our network?
