RE: Pentesting a Citrix Network

From: Greg (greg@hoobie.net)
Date: 03/05/02


From: "Greg" <greg@hoobie.net>
To: "Erlend J. Leiknes" <nookie@online.no>, <pen-test@securityfocus.com>, "Franklin DeMatto" <franklin.lists@qDefense.com>
Date: Tue, 5 Mar 2002 18:32:06 -0000

Yes, that's what I have done in the past. The HTTP server is related to the
'published applications' function within Citrix. If you take a Citrix ICA
client and attempt to list the published apps on a specified server you will
see an HTTP POST request go to the Citrix HTTP server, I don't remember the
script name but it is in a /scripts/ directory.

Set up your Citrix connection, from the client, as a TCP/IP+HTTP connection
and you will be able to examine the requests (which are cleartext)

cheers

Greg

> -----Original Message-----
> From: Erlend J. Leiknes [mailto:nookie@online.no]
> Sent: 05 March 2002 05:42
> To: pen-test@securityfocus.com; Franklin DeMatto
> Subject: Re: Pentesting a Citrix Network
>
>
> What about setting up a citrix client, and then sniffing the data between
> them?
>
>
> ----- Original Message -----
> From: "Franklin DeMatto" <franklin.lists@qDefense.com>
> To: <pen-test@securityfocus.com>
> Sent: Sunday, March 03, 2002 10:53 PM
> Subject: Pentesting a Citrix Network
>
>
> > I'm pentesting a network that includes two Citrix servers on
> Win 2k. As I
> > have no experience whatsoever with Citrix, I thought I'd ask if
> anyone can
> > help me out. The servers listen on port 80, with the following banners:
> >
> > HEAD / HTTP/1.0
> >
> > HTTP/1.1 400 Bad request
> > Server: Citrix Web PN Server
> > Date: xxxx
> > Connection: Close
> >
> > They also listen on the 1494 port (which is designated for citrix)
> >
> > I was unable to get it to respond to any HTTP request, by hand or with a
> > browser.
> >
> > I'd appreciate if anyone could help me with some of the following
> questions
> > (again, they may be basic, I have never used Citrix):
> >
> > Which Citrix product is it? Is there a way to fingerprint it?
> > How do I get it to respond to HTTP requests?
> > Are there any information disclosure possibilites? How about
> > vulnerabilities (i.e. buffer overflows, etc.)?
> >
> > Any help would be very appreciated!
> >
> >
> >
> > Franklin DeMatto
> > Senior Analyst, qDefense Penetration Testing
> > http://qDefense.com
> > qDefense: Making Security Accessible
> >
> >
> >
> --------------------------------------------------------------------------
> --
> > This list is provided by the SecurityFocus Security Intelligence Alert
> (SIA)
> > Service. For more information on SecurityFocus' SIA service which
> > automatically alerts you to the latest security vulnerabilities please
> see:
> > https://alerts.securityfocus.com/
> >
> >
>
>
> ------------------------------------------------------------------
> ----------
> This list is provided by the SecurityFocus Security Intelligence
> Alert (SIA)
> Service. For more information on SecurityFocus' SIA service which
> automatically alerts you to the latest security vulnerabilities
> please see:
> https://alerts.securityfocus.com/
>

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: Terminal Services question
    ... improving security over that right away by renaming the administrator ... >> essentially anyone can connect via RDP to your server right through your ... >> involving Citrix are using the Citrix Extranet client and NFuse. ... >> server you can control access to applications on a per application basis ...
    (microsoft.public.windows.server.general)
  • Re: change IE security levels for LOCAL users on Win 2k3 Server
    ... I know these are local users, but is it a domain server or a workgroup server? ... Citrix is using LOCAL User profiles to login via Terminal Services ... QuickBooks complains about 5 times about various IE security issues ... don't have the permissions to change IE security settings. ...
    (microsoft.public.windows.server.general)
  • Re: oledb
    ... I use a Citrix Farm and there is NO DIRECT USE OF TABLES FROM ANY USER! ... you can access the server from anywhere in the world and still have the same exact security. ... In order to improve security, I'm considering putting the data on a Windows Server 2003 machine and accessing it via OleDB. ...
    (microsoft.public.fox.programmer.exchange)
  • Re: Simulate mouse movement?
    ... If yours is anything like Citrix's implementation of this security ... We wanted to leave them on overnight logged into Citrix to run ... > The screensaver is disabled and I've set the screen to never go blank ... > the mouse by API calls. ...
    (microsoft.public.vb.general.discussion)
  • Re: Least User Priviledges for Network Administrators
    ... We've already covered most of the other security issues that you mentioned. ... We use Citrix in place of TS. ... administer local PCs have rights only on the PC--those accounts have no ... or helpdesk work should never be done under a Domain Admin account, ...
    (microsoft.public.windowsxp.security_admin)