Securing Citrix XenApp Server in the Enterprise

Securing Citrix XenApp Server in the Enterprise

4.11 - 1251 ratings - Source

Citrix Presentation Server allows remote users to work off a network server as if they weren't remote. That means: Incredibly fast access to data and applications for users, no third party VPN connection, and no latency issues. All of these features make Citrix Presentation Server a great tool for increasing access and productivity for remote users. Unfortunately, these same features make Citrix just as dangerous to the network it's running on. By definition, Citrix is granting remote users direct access to corporate servers?..achieving this type of access is also the holy grail for malicious hackers. To compromise a server running Citrix Presentation Server, a hacker need not penetrate a heavily defended corporate or government server. They can simply compromise the far more vulnerable laptop, remote office, or home office of any computer connected to that server by Citrix Presentation Server. All of this makes Citrix Presentation Server a high-value target for malicious hackers. And although it is a high-value target, Citrix Presentation Servers and remote workstations are often relatively easily hacked, because they are often times deployed by overworked system administrators who haven't even configured the most basic security features offered by Citrix. qThe problem, in other words, isn't a lack of options for securing Citrix instances; the problem is that administrators aren't using them.q (eWeek, October 2007). In support of this assertion Security researcher Petko D. Petkov, aka qpdpq, said in an Oct. 4 posting that his recent testing of Citrix gateways led him to qtonsq of qwide-openq Citrix instances, including 10 on government domains and four on military domains. * The most comprehensive book published for system administrators providing step-by-step instructions for a secure Citrix Presentation Server. * Special chapter by Security researcher Petko D. Petkov'aka qpdp detailing tactics used by malicious hackers to compromise Citrix Presentation Servers. * Companion Web site contains custom Citrix scripts for administrators to install, configure, and troubleshoot Citrix Presentation Server.C:\agt;shadow RDP-Tcp#7 /SERVER: /V Your session may appear frozen while the remote control approval is ... Error code 7051 Error [7051]: The requested session is not configured to allow remote control. ... If you are on a Dell laptop like mine, you need to use Ctrl+Fn+0 to simulate that command. Maximizing Your SQL Compromise with Terminal Server When performing a penetration test, anbsp;...

Title:Securing Citrix XenApp Server in the Enterprise
Author:Tariq Azad
Publisher:Syngress - 2008-08-08


You Must CONTINUE and create a free account to access unlimited downloads & streaming