RE: Citrix NFuse 1.6

From: Jeff Mills (Jeff.Millsat_private)
Date: Tue Jan 22 2002 - 13:43:11 PST

  • Next message: Michael Wojcik: "RE: remote memory reading through tcp/icmp"

    Tom and all,
    I could not reproduce this problem.
    My NFuse 1.6 server seems to redirect to the login page if I try to connect
    directly to applist.asp.
    
    Cheers,
    
    Jeff Mills
    
    
    
    
    -----Original Message-----
    From: Tom.Lyneat_private [mailto:Tom.Lyneat_private]
    Sent: Wednesday, 23 January 2002 2:58 
    To: bugtraqat_private
    Subject: Citrix NFuse 1.6
    
    
    Dear Reader,
    
          It seems if you go to an NFuse servers 'applist.asp' page without
    first authenticating it reveals a list of all the applications that are
    configured as published applications. Seems like an easily preventable
    information leak from a default setup,
    
    Rgds,
    Tom Lyne
    



    This archive was generated by hypermail 2b30 : Tue Jan 22 2002 - 14:28:49 PST