Hacking Citrix Faq

From: wirepair (wirepairat_private)
Date: Thu Sep 26 2002 - 18:04:57 PDT

  • Next message: Daniel R. Ome: "Re: IIL Advisory: Reverse traversal vulnerability in Monkey (0.1.4) HTTP server"

    Over the past few months I've encountered Citrix in many 
    occasions. I wrote this paper better detailing how one 
    might
    subvert the security functions in place to run 
    applications they should most likely not be running. I 
    Think I have uncovered a flaw in the way Citrix publishes 
    applications, but to talk with their technicians, it would 
    have costed me 400$. Maybe this paper will change the way 
    they handle security incidents.
    
    It can be found at 
    http://sh0dan.org/files/hackingcitrix.txt
    
    -wire
    _____________________________
    For the best comics, toys, movies, and more,
    please visit <http://www.tfaw.com/?qt=wmf>
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/
    



    This archive was generated by hypermail 2b30 : Thu Sep 26 2002 - 19:04:01 PDT