Skip to main content
Ninad
New Member
July 20, 2020
Question

Obfuscate HTTP headers" which need to hides the HTTP server banner.

  • July 20, 2020
  • 1 reply
  • 3371 views

We found below vulnerability in audit point 

"Fortigate - Obfuscate HTTP headers" which need to hides the HTTP server banner.

Kindly let me know what action need to be taken to mitigate this

 

    1 reply

    Yurisk
    SuperUser
    SuperUser
    July 21, 2020

    If you mean the HTTP(S) admin GUI of the Fortigate itself, then once upon a time tehre was such settings which is gone now: 

    config system global

    set http-obfuscate {none | header-only | modified | no-error}

     

    https://help.fortinet.com/fos50hlp/52data/Content/FortiOS/fortigate-system-administration-52/Advanced%20Concepts/advanced.htm#Obfuscat

     

    If you mean obfuscate headers sent by HTTP servers behind the FOrtigate - there is no such option, Fortinet have Fortiweb for that.