Jump to content
The Inquirer-Home

Citrix leaves gaping holes in web sites

US government, military sites vulnerable, bloke reckons
Tuesday, 9 October 2007, 15:31

CITRIX SERVERS running US government and military websites are full of security holes, says a security researcher quoted in a story at Eweek.

Petko Petkov writes that his recent testing of Citrix gateways found "tons" of vulnerable instances, including 10 in US government domains and four in US military domains.

The basic problem, apparently, is that Citrix services that once started out on secure LANs ended up over time using routable protocols on Internet facing servers that weren't properly firewalled.

Anyone with Citrix client software or hacking tools can access formerly secure internal services that are now wide open to the Internet.

More here. ยต

Share this:

Comments
Making Available...

Hmmm "Making Available...."

Go get em...

I'm sure you find a song there somewhere.

"Cases such as this remind us strong enforcement is a significant part of the effort to eliminate piracy, and that we have an effective legal system in the U.S. that enables rights holders to protect their intellectual property."

posted by : Pete, 09 October 2007 Complain about this comment
Advertisement
Subscribe to the INQ Newsletter
Sign-up for the INQBot weekly newsletter
Click here to sign up Existing user
Advertisement
INQ Poll

Christmas computer sales

Will you be buying a new computer this Christmas?