Contributes to PCI Compliance
ServerMask provides application-layer error suppression for PCI compliance.
Masks Server Name Header
ServerMask will mask the Server name header in a number of ways:
- Remove altogether
- Replace with one of 30 other Web server signatures
- Replace with a custom server name you create
- Select multiple false Web server signatures and randomize the response (you select how often a response is refreshed).
ServerMask allows for multiple default profiles and the ability to create custom profiles, allowing unique settings to be applied per domain.
Information masking encourages misguided exploits, snaring attackers with your firewalls and Intrusion Detection System. ServerMask augments these defenses to build more secure networks and return better results on security audits.
Modify Cookie Values
The ASP session ID cookie, used by the Session object to maintain client state, is a dead giveaway to the type of server you are running. ServerMask can modify your cookie values so that they are generic in nature and non identifiable.
Custom Error Pages
Default messages, pages and scripts of all kinds often contain clues to server identity. ServerMask custom error pages mask that information for better security.
Rewrite Identifying Session Cookie Names
ServerMask will rewrite identifying session cookie names, such as ASPSessionID and ASP.NET_SessionId, using one or more alternative names and fabricate decoy cookies to further confuse attackers. ServerMask utilizes One-to-many cookie masking.
Remove unnecessary HTTP headers
ServerMask removes unnecessary HTTP headers, such as PUBLIC, X-POWERED-BY and others.
Emulate Other Server Data
ServerMask will emulate the ETAG and ALLOW header formats of non-IIS servers. (As well as Apache's HTTP header order.)
Remove Identifying File Extensions
ServerMask removes identifying file extensions, such as .asp, .aspx and other Microsoft technologies from source code and URL display.
Ease of Use
Completely redesigned user interface, featuring 100% managed code.
Decoys & Error Messages
ServerMask provides Auto-generated decoy cookies and headers, and customizable HTTP error messages.
Diagnostics & Validation
Online diagnostic tool for checking page cacheability and validation tool provided for checking syntax of rule statements
Rewrite 404 & Application-layer Errors
ServerMask suppresses info leakage by converting 500-range errors to 404 errors, then presenting custom 404 responses.