<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: 0day: Hacking secured CITRIX from outside</title>
	<atom:link href="http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: DH</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-121833</link>
		<dc:creator>DH</dc:creator>
		<pubDate>Wed, 14 May 2008 10:37:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-121833</guid>
		<description>Here is the fix, nice job PDP :-D

XenApp 4.5
http://support.citrix.com/article/CTX116954</description>
		<content:encoded><![CDATA[<p>Here is the fix, nice job PDP :-D</p>
<p>XenApp 4.5<br />
<a href="http://support.citrix.com/article/CTX116954" rel="nofollow">http://support.citrix.com/article/CTX116954</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kaustubh Kumar</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-117085</link>
		<dc:creator>Kaustubh Kumar</dc:creator>
		<pubDate>Thu, 20 Mar 2008 23:15:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-117085</guid>
		<description>Hi All,
I need help in hacking citrix which can allow me to open websites in the citrix metaframe.</description>
		<content:encoded><![CDATA[<p>Hi All,<br />
I need help in hacking citrix which can allow me to open websites in the citrix metaframe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Security Researcher Warns About Citrix Vulnerability</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-74219</link>
		<dc:creator>Security Researcher Warns About Citrix Vulnerability</dc:creator>
		<pubDate>Tue, 20 Nov 2007 06:58:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-74219</guid>
		<description>[...] &#8220;cutting-edge think tank&#8221; and a &#8220;creative hacker organization,&#8221; has &#171;www.gnucitizen.org&#187; about a cross-site request forgery attack that can be made in conjunction with a malicious [...]</description>
		<content:encoded><![CDATA[<p>[...] &#8220;cutting-edge think tank&#8221; and a &#8220;creative hacker organization,&#8221; has &laquo;www.gnucitizen.org&raquo; about a cross-site request forgery attack that can be made in conjunction with a malicious [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-61715</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 26 Oct 2007 06:28:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-61715</guid>
		<description>Noob I haven&#039;t tested that but it should work in theory.</description>
		<content:encoded><![CDATA[<p>Noob I haven&#8217;t tested that but it should work in theory.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Noob</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-61579</link>
		<dc:creator>Noob</dc:creator>
		<pubDate>Thu, 25 Oct 2007 20:33:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-61579</guid>
		<description>Question:

If the user does not have pass through enabled, but does have stored credentials in the client- (username, password, domain) - will the attack still work?</description>
		<content:encoded><![CDATA[<p>Question:</p>
<p>If the user does not have pass through enabled, but does have stored credentials in the client- (username, password, domain) &#8211; will the attack still work?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackathology</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-60591</link>
		<dc:creator>hackathology</dc:creator>
		<pubDate>Mon, 22 Oct 2007 17:10:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-60591</guid>
		<description>i found out the clue</description>
		<content:encoded><![CDATA[<p>i found out the clue</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackathology</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-60590</link>
		<dc:creator>hackathology</dc:creator>
		<pubDate>Mon, 22 Oct 2007 17:09:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-60590</guid>
		<description>got it pdp. I found it</description>
		<content:encoded><![CDATA[<p>got it pdp. I found it</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-60542</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 22 Oct 2007 13:54:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-60542</guid>
		<description>hackathology, nope, it is different. you should be able to figure it out though.</description>
		<content:encoded><![CDATA[<p>hackathology, nope, it is different. you should be able to figure it out though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Major Fukup</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-60504</link>
		<dc:creator>Major Fukup</dc:creator>
		<pubDate>Mon, 22 Oct 2007 11:50:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-60504</guid>
		<description>One of the reasons why you should always give users on these systems minimum rights.
Does it require a published desktop?
Which virtual channels do you use?

Regards M.F.</description>
		<content:encoded><![CDATA[<p>One of the reasons why you should always give users on these systems minimum rights.<br />
Does it require a published desktop?<br />
Which virtual channels do you use?</p>
<p>Regards M.F.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackathology</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-60476</link>
		<dc:creator>hackathology</dc:creator>
		<pubDate>Mon, 22 Oct 2007 10:20:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-60476</guid>
		<description>Is this the same vulnerability found here?

http://support.citrix.com/article/CTX112589</description>
		<content:encoded><![CDATA[<p>Is this the same vulnerability found here?</p>
<p><a href="http://support.citrix.com/article/CTX112589" rel="nofollow">http://support.citrix.com/article/CTX112589</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-57501</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 12 Oct 2007 08:40:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-57501</guid>
		<description>Folk, apparently CITRIX has removed the YouTube videos due to some copyright violation. This is strange and the same time not the right way to handle security advisories. Still haven&#039;t got any response from them around the issue and I seriously doubt that this will ever happen. However, I am going to keep the POC private for now and give them a chance to react on the in sensible way.</description>
		<content:encoded><![CDATA[<p>Folk, apparently CITRIX has removed the YouTube videos due to some copyright violation. This is strange and the same time not the right way to handle security advisories. Still haven&#8217;t got any response from them around the issue and I seriously doubt that this will ever happen. However, I am going to keep the POC private for now and give them a chance to react on the in sensible way.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wekrid</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-57490</link>
		<dc:creator>wekrid</dc:creator>
		<pubDate>Fri, 12 Oct 2007 07:47:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-57490</guid>
		<description>will this hack also work with csg and cags?</description>
		<content:encoded><![CDATA[<p>will this hack also work with csg and cags?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-57268</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 11 Oct 2007 18:40:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-57268</guid>
		<description>no user interaction is required!</description>
		<content:encoded><![CDATA[<p>no user interaction is required!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lol</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-57265</link>
		<dc:creator>lol</dc:creator>
		<pubDate>Thu, 11 Oct 2007 18:14:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-57265</guid>
		<description>it just seems to be the category clickmyexecutableiwonthurt &quot;exploit&quot;. unfortunately we can&#039;t patch users.</description>
		<content:encoded><![CDATA[<p>it just seems to be the category clickmyexecutableiwonthurt &#8220;exploit&#8221;. unfortunately we can&#8217;t patch users.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-57175</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 11 Oct 2007 11:22:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-57175</guid>
		<description>hellboy726, interesting site you have there! reminds  me of 1998... but I like it.</description>
		<content:encoded><![CDATA[<p>hellboy726, interesting site you have there! reminds  me of 1998&#8230; but I like it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hellboy726</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-57173</link>
		<dc:creator>hellboy726</dc:creator>
		<pubDate>Thu, 11 Oct 2007 11:15:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-57173</guid>
		<description>Nice!</description>
		<content:encoded><![CDATA[<p>Nice!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-57169</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Thu, 11 Oct 2007 11:00:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-57169</guid>
		<description>rootkid, there is nothing on the horizon for me in europe for the rest of this year. feel free to contact me through!</description>
		<content:encoded><![CDATA[<p>rootkid, there is nothing on the horizon for me in europe for the rest of this year. feel free to contact me through!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rootkid</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-57164</link>
		<dc:creator>rootkid</dc:creator>
		<pubDate>Thu, 11 Oct 2007 10:49:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-57164</guid>
		<description>Oh bummer. Man, I was investigating the same stuff (citrix that is) at the moment, and somehow you are always a leap ahead. I hate that...:) Anyhow, good work as always. I would really like to have a chat with you someday if you happen to be around (any con you are on this year in europe?). Probably we can share ideas, if you like. 
Cheers.</description>
		<content:encoded><![CDATA[<p>Oh bummer. Man, I was investigating the same stuff (citrix that is) at the moment, and somehow you are always a leap ahead. I hate that&#8230;:) Anyhow, good work as always. I would really like to have a chat with you someday if you happen to be around (any con you are on this year in europe?). Probably we can share ideas, if you like.<br />
Cheers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zeridon</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-57126</link>
		<dc:creator>zeridon</dc:creator>
		<pubDate>Thu, 11 Oct 2007 07:10:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-57126</guid>
		<description>Looks nice,

and also i see a storm brewing ... smth. like the 0day pdf.</description>
		<content:encoded><![CDATA[<p>Looks nice,</p>
<p>and also i see a storm brewing &#8230; smth. like the 0day pdf.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vindic</title>
		<link>http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside/comment-page-1/#comment-57090</link>
		<dc:creator>vindic</dc:creator>
		<pubDate>Thu, 11 Oct 2007 00:25:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/0day-hacking-secured-citrix-from-outside#comment-57090</guid>
		<description>Yes, very nice, thnx for good work ;)</description>
		<content:encoded><![CDATA[<p>Yes, very nice, thnx for good work ;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
