On Sep 10, 2008, at 11:05 AM, Steve Templists wrote:

> Does anyone know how/if this vulnerability can be prevented?  The  
> plugin doesn't provide any recommendations and I don't have access  
> to a Citrix server (this was found on a clients network) to develop  
> any of my own.

I don't off-hand, but notice that the hackingcitrix document includes  
a section entitled "Securing Citrix" with some tips.

> Also, the risk factor is a "Medium" but doesn't say the CVV2 style  
> rating, would this still be a medium with the new rating system?

Yes.

> BTW..The link for more information is no longer valid.  The new link  
> is:  http://sh0dan.org/oldfiles/hackingcitrix.html

Thanks. I'll update the plugin shortly with the new link, a CVSS  
score, and revise the description to agree with our more recent plugins.

George
-- 
[EMAIL PROTECTED]



_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to