Themes & Channels

Grab our RSS feed !

Stay informed !
Subscribe to our FREE newsletters...
 The Security Newsletter
 The Storage Newsletter

/images/public/sites/SecurityNewsletter.com/articles/illustrations/vulnerabilites_100.gif

Are Citrix gateways safe enough ?

analysisJump right to our comments

A security researcher warns of many security flaws he found during testing of Citrix gateways.

Petko D. Petkov (aka PDP), a researcher at GNU Citizen, who writes in a blog, posts that he found many vulnerabilities
during recent testing of Citrix gateways.

"The Internet is full of wide open CITRIX gateways. This is madness!. The other day I was performing some CITRIX testing, so I had a lot of fun with hacking into GUIs, which, as most of you probably know, are trivial to break into. I did play around with .ICA files as well, just to make sure that the client is not affected by some obvious client-side vulnerabilities. This exercise led me to reevaluate great many things about ICA (Independent Computing Architecture). When querying Google and Yahoo for public .ICA files, I was presented with tones of wide open services, some of which were located on .gov and .mil domains" writes PDP.

He also noted :

"Just by looking into Google, I was able to find 114 wide open CITRIX instances: 10 .gov, 4 .mil, 20 .edu, 27 .com, etc… The research was conducted offline, therefore there might be some false positives. Among the services discovered, there were several critical applications which looked so interesting that I didn’t even dare look at them. With a similar success, attackers can perform just simple port scans for service port 1494. The steps described above apply."

His post:

http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/

Our comments :

PDP's warnings should be taken seriously as this researcher already uncovered flaws in Adobe Acrobat Reader, in Apple Quicktime, and in Google Gmail. We're now waiting for the industry's reaction to those findings. But cautious companies might want to take a safe stance and begin assessing their .ica use.

News Options >

AddThis Social Bookmark Button

print this news Print this news

Check-out our sister site !
StorageNewsletter, the Daily Breaking News for the Worldwide IT Storage Industry

Into IAM ?

iam_small

The IAM 2008 Series

SecurityNewsletter interviews major Identity & Access Management players to give you the lead on what IAM will be in 2008.

Don't Miss Out !