<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: CITRIX: Owning the Legitimate Backdoor</title>
	<atom:link href="http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Fri, 29 Aug 2008 18:53:50 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: ikkuhqhp</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-122075</link>
		<dc:creator>ikkuhqhp</dc:creator>
		<pubDate>Sun, 18 May 2008 09:57:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-122075</guid>
		<description>pdp, I was reading this post but found that the youtube link doesn't work. Could you explain "escaping windows GUI" again please?</description>
		<content:encoded><![CDATA[<p>pdp, I was reading this post but found that the youtube link doesn&#8217;t work. Could you explain &#8220;escaping windows GUI&#8221; again please?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Citrix Prezantasyon Sunucusu iÃ§in Yama &#124; VirÃ¼s GÃ¼venlik Haberleri</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-86876</link>
		<dc:creator>Citrix Prezantasyon Sunucusu iÃ§in Yama &#124; VirÃ¼s GÃ¼venlik Haberleri</dc:creator>
		<pubDate>Sat, 15 Dec 2007 10:17:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-86876</guid>
		<description>[...] gÃ¼venlik aÃ§Ä±ÄŸÄ± duyurusu: http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/ Citrix gÃ¼venlik bÃ¼lteni: [...]</description>
		<content:encoded><![CDATA[<p>[...] gÃ¼venlik aÃ§Ä±ÄŸÄ± duyurusu: <a href="http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/" rel="nofollow">http://www.gnucitizen.org/blog.....-backdoor/</a> Citrix gÃ¼venlik bÃ¼lteni: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TesCitrixOuPas &#187; Blog Archive &#187; Citrix, trou de sÃ©curitÃ© ou mauvaise gestion des administrateurs Citrix ?</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-78422</link>
		<dc:creator>TesCitrixOuPas &#187; Blog Archive &#187; Citrix, trou de sÃ©curitÃ© ou mauvaise gestion des administrateurs Citrix ?</dc:creator>
		<pubDate>Wed, 28 Nov 2007 22:03:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-78422</guid>
		<description>[...] le site GNUCITIZEN, un chercheur en sÃ©curitÃ© en faisant une simple recherche sur Google est tombÃ© sur une floppÃ© [...]</description>
		<content:encoded><![CDATA[<p>[...] le site GNUCITIZEN, un chercheur en sÃ©curitÃ© en faisant une simple recherche sur Google est tombÃ© sur une floppÃ© [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: newKid</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-73277</link>
		<dc:creator>newKid</dc:creator>
		<pubDate>Mon, 19 Nov 2007 03:30:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-73277</guid>
		<description>I am not a hacker, just a college kid, studying networking, programming, security, the like. I am researching Citrix for a security paper. I clicked on some of these links, to see what would happen, as the read is seriously intriguing to me. Most of them you can't actually get to. One came up but gave me an error and did not display. Please explain; are you telling me that by clicking the links that are returned in the search, that you are actually accessing information running on the server? There is no one on the other end that can see or be alerted of the fact that some remote user is actually getting in unauthenticated? I don't understand. How does this actually work out?</description>
		<content:encoded><![CDATA[<p>I am not a hacker, just a college kid, studying networking, programming, security, the like. I am researching Citrix for a security paper. I clicked on some of these links, to see what would happen, as the read is seriously intriguing to me. Most of them you can&#8217;t actually get to. One came up but gave me an error and did not display. Please explain; are you telling me that by clicking the links that are returned in the search, that you are actually accessing information running on the server? There is no one on the other end that can see or be alerted of the fact that some remote user is actually getting in unauthenticated? I don&#8217;t understand. How does this actually work out?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-63063</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 30 Oct 2007 07:21:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-63063</guid>
		<description>Intrigued, absolutely!</description>
		<content:encoded><![CDATA[<p>Intrigued, absolutely!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Intrigued</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-62957</link>
		<dc:creator>Intrigued</dc:creator>
		<pubDate>Tue, 30 Oct 2007 00:56:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-62957</guid>
		<description>I found it interesting that some of the servers have user names and domain names in the config files. After looking around I found that some of them give you a remote desktop without authentication with full access by using a user name and domain name (could be dead wrong and it just gives you the remote desktop anyways but none the less its still a blatant hole)</description>
		<content:encoded><![CDATA[<p>I found it interesting that some of the servers have user names and domain names in the config files. After looking around I found that some of them give you a remote desktop without authentication with full access by using a user name and domain name (could be dead wrong and it just gives you the remote desktop anyways but none the less its still a blatant hole)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Network Security Podcast, Episode 81 &#124; securosis.com</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-59431</link>
		<dc:creator>Network Security Podcast, Episode 81 &#124; securosis.com</dc:creator>
		<pubDate>Thu, 18 Oct 2007 16:23:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-59431</guid>
		<description>[...] Citrix; Owning the legitimate backdoor [...]</description>
		<content:encoded><![CDATA[<p>[...] Citrix; Owning the legitimate backdoor [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bbb</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58567</link>
		<dc:creator>Bbb</dc:creator>
		<pubDate>Mon, 15 Oct 2007 15:06:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58567</guid>
		<description>Absolutely very concerning, the fact that you can get Numb-Nut administrators. 

As I mentioned above....

http://search.yahoo.com/search.....ension:rdp

http://www.google.com/search?q=ext:rdp

.....you get the same numb-nuts administrating plain old Terminal services as well as any other product.

The first line of your article 'The Internet is full of wide open CITRIX gateways' probably put the Sh$ts up many a CITRIX administrator because they implement true CITRIX gateways (that only open for the correct people). I hope people reading this article realise that this is not the way to implement CITRIX for remote access.

I can't believe the amount of people who don't follow simple IT Security recommended practices. This is probably why your article should be entitled 'Beware There are Numb-Nut Administrators everywhere!!' ;-)

Bbb</description>
		<content:encoded><![CDATA[<p>Absolutely very concerning, the fact that you can get Numb-Nut administrators. </p>
<p>As I mentioned above&#8230;.</p>
<p><a href="http://search.yahoo.com/search.....ension:rdp" rel="nofollow">http://search.yahoo.com/search&#8230;..ension:rdp</a></p>
<p><a href="http://www.google.com/search?q=ext:rdp" rel="nofollow">http://www.google.com/search?q=ext:rdp</a></p>
<p>&#8230;..you get the same numb-nuts administrating plain old Terminal services as well as any other product.</p>
<p>The first line of your article &#8216;The Internet is full of wide open CITRIX gateways&#8217; probably put the Sh$ts up many a CITRIX administrator because they implement true CITRIX gateways (that only open for the correct people). I hope people reading this article realise that this is not the way to implement CITRIX for remote access.</p>
<p>I can&#8217;t believe the amount of people who don&#8217;t follow simple IT Security recommended practices. This is probably why your article should be entitled &#8216;Beware There are Numb-Nut Administrators everywhere!!&#8217; ;-)</p>
<p>Bbb</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Citrix holes endanger Government and Military systems - spyware news</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58562</link>
		<dc:creator>Citrix holes endanger Government and Military systems - spyware news</dc:creator>
		<pubDate>Mon, 15 Oct 2007 14:05:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58562</guid>
		<description>[...] into Citrix GUIs and playing with .ica files. He kindly posted the results of this rampage on his blog. What he did was he tried searching for public .ICAs in google and yahoo and found &#34;tons&#34; [...]</description>
		<content:encoded><![CDATA[<p>[...] into Citrix GUIs and playing with .ica files. He kindly posted the results of this rampage on his blog. What he did was he tried searching for public .ICAs in google and yahoo and found &quot;tons&quot; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Day Today &#187; Blog Archive &#187; Citrix backdoors easy to find</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58560</link>
		<dc:creator>The Day Today &#187; Blog Archive &#187; Citrix backdoors easy to find</dc:creator>
		<pubDate>Mon, 15 Oct 2007 13:47:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58560</guid>
		<description>[...] gateways, which are often unsecured - allowing a hacker to get a command prompt on the servers. This article explains how, and includes a video showing how to get a command prompt from the calculator [...]</description>
		<content:encoded><![CDATA[<p>[...] gateways, which are often unsecured - allowing a hacker to get a command prompt on the servers. This article explains how, and includes a video showing how to get a command prompt from the calculator [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58528</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 15 Oct 2007 10:02:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58528</guid>
		<description>Bbb, but it is still concerning isn't it? which was the point of the post! right?</description>
		<content:encoded><![CDATA[<p>Bbb, but it is still concerning isn&#8217;t it? which was the point of the post! right?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bbb</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58525</link>
		<dc:creator>Bbb</dc:creator>
		<pubDate>Mon, 15 Oct 2007 09:58:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58525</guid>
		<description>How about 'hacking' Windows Terminal services

http://search.yahoo.com/search?p=originurlextension:rdp

http://www.google.com/search?q=ext:rdp

As mentioned above this isn't a hack just someone who left the front door open for someone to easily walk through</description>
		<content:encoded><![CDATA[<p>How about &#8216;hacking&#8217; Windows Terminal services</p>
<p><a href="http://search.yahoo.com/search?p=originurlextension:rdp" rel="nofollow">http://search.yahoo.com/search.....ension:rdp</a></p>
<p><a href="http://www.google.com/search?q=ext:rdp" rel="nofollow">http://www.google.com/search?q=ext:rdp</a></p>
<p>As mentioned above this isn&#8217;t a hack just someone who left the front door open for someone to easily walk through</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58521</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Mon, 15 Oct 2007 09:34:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58521</guid>
		<description>the videos can be found at the bottom of this post: http://www.gnucitizen.org/blog/hacking-citrix-the-forceful-way/</description>
		<content:encoded><![CDATA[<p>the videos can be found at the bottom of this post: <a href="http://www.gnucitizen.org/blog/hacking-citrix-the-forceful-way/" rel="nofollow">http://www.gnucitizen.org/blog.....ceful-way/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58520</link>
		<dc:creator>Alan</dc:creator>
		<pubDate>Mon, 15 Oct 2007 09:28:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58520</guid>
		<description>Hack is a hack. Doesn't matter whether you find it sophisticated or not. If you can get to .mil sites with it, that's obviously something critical.

i didnt see the video btw, can someone fix the link:

&lt;blockquote&gt;This video is no longer available due to a copyright claim by Citrix Systems, Inc.&lt;/blockquote&gt;

what copyright? :)</description>
		<content:encoded><![CDATA[<p>Hack is a hack. Doesn&#8217;t matter whether you find it sophisticated or not. If you can get to .mil sites with it, that&#8217;s obviously something critical.</p>
<p>i didnt see the video btw, can someone fix the link:</p>
<blockquote><p>This video is no longer available due to a copyright claim by Citrix Systems, Inc.</p></blockquote>
<p>what copyright? :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stupidisasstupiddoes</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58118</link>
		<dc:creator>stupidisasstupiddoes</dc:creator>
		<pubDate>Sat, 13 Oct 2007 20:58:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-58118</guid>
		<description>Stupid is as stupid does.  You can lead a horse, but making it drink is another issue.  Secure Gateway and Access Gateway have been available for years.  If the Citrix admin is getting away with exposing a Presentation Server in the DMZ, then they deserve to be hacked.</description>
		<content:encoded><![CDATA[<p>Stupid is as stupid does.  You can lead a horse, but making it drink is another issue.  Secure Gateway and Access Gateway have been available for years.  If the Citrix admin is getting away with exposing a Presentation Server in the DMZ, then they deserve to be hacked.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clear &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-57952</link>
		<dc:creator>Clear &#124; GNUCITIZEN</dc:creator>
		<pubDate>Sat, 13 Oct 2007 12:39:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-57952</guid>
		<description>[...] first general misconception is regarding the CITRIX posts. Let&#8217;s start with CITRIX: Owning the Legitimate Backdoor, shall we? A lot of GNUCITIZEN&#8217;s readers thought that I am showing new attack techniques. No, [...]</description>
		<content:encoded><![CDATA[<p>[...] first general misconception is regarding the CITRIX posts. Let&#8217;s start with CITRIX: Owning the Legitimate Backdoor, shall we? A lot of GNUCITIZEN&#8217;s readers thought that I am showing new attack techniques. No, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-57869</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sat, 13 Oct 2007 08:44:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-57869</guid>
		<description>rjhoward, one word: gateways! make sure that you use nfuse or whatever else you want but just never, ever, expose 1494/UDP/TCP on the Internet. Segment as much as possible.

Unfortunately, all this will make your work 100% more intensive. So, there is no space for laziness :)</description>
		<content:encoded><![CDATA[<p>rjhoward, one word: gateways! make sure that you use nfuse or whatever else you want but just never, ever, expose 1494/UDP/TCP on the Internet. Segment as much as possible.</p>
<p>Unfortunately, all this will make your work 100% more intensive. So, there is no space for laziness :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rjhoward</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-57669</link>
		<dc:creator>rjhoward</dc:creator>
		<pubDate>Fri, 12 Oct 2007 19:13:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-57669</guid>
		<description>Ok, you have my attention and the attention of everyone in my organization.  How can we tighten things up?  What is this lazy administrator doing to contribute to the issue and how can I improve?</description>
		<content:encoded><![CDATA[<p>Ok, you have my attention and the attention of everyone in my organization.  How can we tighten things up?  What is this lazy administrator doing to contribute to the issue and how can I improve?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-57588</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 12 Oct 2007 14:44:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-57588</guid>
		<description>Maverick, since it is known for ages.... why didn't you flagged it then? &lt;strong&gt;I am not releasing a new vulnerability!&lt;/strong&gt;

&lt;div class="message"&gt;All I am saying is that there are wide open CITRIX services out there which are susceptible to attack! on government and military facilities btw!!!&lt;/div&gt;

BTW, what do you define as hacking? Cuz I am tired of listing to people who define reverse engineering and C exploit writing as hacking. That has nothing to do with hacking. That's stupid methodology everyone can learn in a month. There is nothing creative about it!</description>
		<content:encoded><![CDATA[<p>Maverick, since it is known for ages&#8230;. why didn&#8217;t you flagged it then? <strong>I am not releasing a new vulnerability!</strong></p>
<div class="message">All I am saying is that there are wide open CITRIX services out there which are susceptible to attack! on government and military facilities btw!!!</div>
<p>BTW, what do you define as hacking? Cuz I am tired of listing to people who define reverse engineering and C exploit writing as hacking. That has nothing to do with hacking. That&#8217;s stupid methodology everyone can learn in a month. There is nothing creative about it!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Citrix Internet Gateways - Critical need to lock these down - Harry Waldron - My IT Forums Blog</title>
		<link>http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-57572</link>
		<dc:creator>Citrix Internet Gateways - Critical need to lock these down - Harry Waldron - My IT Forums Blog</dc:creator>
		<pubDate>Fri, 12 Oct 2007 13:36:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/#comment-57572</guid>
		<description>[...] &#160;&#160;CITRIX: Owning the Legitimate Backdoor&#160;http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/ &#160;&#160;Hacking CITRIX - the forceful [...]</description>
		<content:encoded><![CDATA[<p>[...] &nbsp;&nbsp;CITRIX: Owning the Legitimate Backdoor&nbsp;http://www.gnucitizen.org/blog/citrix-owning-the-legitimate-backdoor/ &nbsp;&nbsp;Hacking CITRIX - the forceful [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
