Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ninad
New Contributor

Obfuscate HTTP headers" which need to hides the HTTP server banner.

We found below vulnerability in audit point 

"Fortigate - Obfuscate HTTP headers" which need to hides the HTTP server banner.

Kindly let me know what action need to be taken to mitigate this

 

1 REPLY 1
Yurisk
SuperUser
SuperUser

If you mean the HTTP(S) admin GUI of the Fortigate itself, then once upon a time tehre was such settings which is gone now: 

config system global

set http-obfuscate {none | header-only | modified | no-error}

 

https://help.fortinet.com/fos50hlp/52data/Content/FortiOS/fortigate-system-administration-52/Advance...

 

If you mean obfuscate headers sent by HTTP servers behind the FOrtigate - there is no such option, Fortinet have Fortiweb for that.

 

https://yurisk.info
https://yurisk.info
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors