Mailing List Archive

Plugin ID 11138 - Citrix published applications
Does anyone know how/if this vulnerability can be prevented? The plugin
doesn't provide any recommendations and I don't have access to a Citrix
server (this was found on a clients network) to develop any of my own.
Also, the risk factor is a "Medium" but doesn't say the CVV2 style rating,
would this still be a medium with the new rating system?

BTW..The link for more information is no longer valid. The new link is:
http://sh0dan.org/oldfiles/hackingcitrix.html

I'd love to be able to provide my client with better information than what
is provided above if anyone can help.

Thanks.
Steve
Re: Plugin ID 11138 - Citrix published applications [ In reply to ]
On Sep 10, 2008, at 11:05 AM, Steve Templists wrote:

> Does anyone know how/if this vulnerability can be prevented? The
> plugin doesn't provide any recommendations and I don't have access
> to a Citrix server (this was found on a clients network) to develop
> any of my own.

I don't off-hand, but notice that the hackingcitrix document includes
a section entitled "Securing Citrix" with some tips.

> Also, the risk factor is a "Medium" but doesn't say the CVV2 style
> rating, would this still be a medium with the new rating system?

Yes.

> BTW..The link for more information is no longer valid. The new link
> is: http://sh0dan.org/oldfiles/hackingcitrix.html

Thanks. I'll update the plugin shortly with the new link, a CVSS
score, and revise the description to agree with our more recent plugins.

George
--
theall@tenablesecurity.com



_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus