Latest Comments
"trend is good antivirus software."
by jack | Dec 3, 2008 7:02 AM
 
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM

Poorly implemented Citrix poses security risk

  • Email a Friend
  • Print Page
By Joy Persaud
Aug 7, 2008 9:59 AM
Tags: Citrix | Risk | flaw |
Organisational security could be at risk if Citrix is not implemented
carefully, according to tests carried out by Global Secure Systems
(GSS), Silver Spring, Md.

Internal systems might be compromised if those without a comprehensive knowledge of its workings install Citrix. GSS found that all the 50 Citrix deployments it tested were vulnerable to arbitrary code execution.

Also, more than 80 per cent exposed commercially sensitive data. Many cases breached the Data Protection Act, and standard security procedures had not been applied to most deployments.

GSS penetration testers, who have sent their findings on to Fort Lauderdale, Fla.-based Citrix, discovered a spreadsheet that held the domain admin passwords for every server at a financial services company, plus quotations, methodologies, terms of business and reports from a number of the firm's competitors.

Of the firms tested, 20 were in the financial services sector.

Robin Hollington, director of consulting for GSS, said the unencrypted information was in a folder protected by access rules.

He said: “Using the access rules we had acquired at the time, we were able to read the information, including passwords, which gave us system administrator access to every server [several hundred] in the organisation. That level of access not only gave us complete control of their systems, but we could have deleted any audit trail we might have left.”

The problem does not lie with Citrix, but rather with its implementation, said Hollington. He advised users to ensure that they are familiar with how to lock down the system and recommended confining access to specific roles.

Last year, the swiftest breach occurred within 15 seconds of logging on. This year, that time has been shaved to less than 10 seconds.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers