Hacking Citrix Faq

From: wirepair (wirepair@roguemail.net)
Date: 09/27/02


From: "wirepair" <wirepair@roguemail.net>
To: vulnwatch@vulnwatch.org, bugtraq@securityfocus.com, vuln-dev@securityfocus.com, pen-test@securityfocus.com
Date: Thu, 26 Sep 2002 18:04:57 -0700

Over the past few months I've encountered Citrix in many
occasions. I wrote this paper better detailing how one
might
subvert the security functions in place to run
applications they should most likely not be running. I
Think I have uncovered a flaw in the way Citrix publishes
applications, but to talk with their technicians, it would
have costed me 400$. Maybe this paper will change the way
they handle security incidents.

It can be found at
http://sh0dan.org/files/hackingcitrix.txt

-wire
_____________________________
For the best comics, toys, movies, and more,
please visit <http://www.tfaw.com/?qt=wmf>

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • RE: SQL
    ... Subject: SQL ... >> This list is provided by the SecurityFocus Security ... For more information on SecurityFocus' SIA service which ... >This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Insurance
    ... property--data beign deemed "intangible" for the purposes of insurance. ... for physical security testing there are often 3rd parties ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • RE: Pen-Testing Lotus Notes/Domino
    ... Subject: Pen-Testing Lotus Notes/Domino ... of document security. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • R: Pen-Testing help (Compaq Insight & htsearch)
    ... This web server happens to be in front of their ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: Application & Iplanet/Apache web server vulnerability and penetration testing
    ... I don't know what to do on the web servers other than delete example ... Any suggestions on iPlanet and Apache security? ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)