Re: Plugin ID 11138 - Citrix published applications

"George A. Theall" <[email protected]>
Newsgroups gmane.comp.security.nessus.general
Message-ID <[email protected]>
On Sep 10, 2008, at 11:05 AM, Steve Templists wrote:

> Does anyone know how/if this vulnerability can be prevented?  The  
> plugin doesn't provide any recommendations and I don't have access  
> to a Citrix server (this was found on a clients network) to develop  
> any of my own.

I don't off-hand, but notice that the hackingcitrix document includes  
a section entitled "Securing Citrix" with some tips.

> Also, the risk factor is a "Medium" but doesn't say the CVV2 style  
> rating, would this still be a medium with the new rating system?

Yes.

> BTW..The link for more information is no longer valid.  The new link  
> is:  http://sh0dan.org/oldfiles/hackingcitrix.html

Thanks. I'll update the plugin shortly with the new link, a CVSS  
score, and revise the description to agree with our more recent plugins.

George
-- 
[email protected]



_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.