Get a Pentest and security assessment of your IT network.

News

SD-PWN Part 2 Citrix SD-WAN Center Another Network Takeover

Citrix SD-WAN has been studied before by Chris Lyne of Tenable. The main bug presented by Tenable was bypassing authentication by using the. Collector endpoint to reach diagnostics. Citrix decided to block this access by adding the. access restriction in the apache configuration at /etc/apache2/sites-enabled-enabled. Bypassing the. drop-point function after the path traversal of the. endpoint will be treated as the. name of the endpoint as a. user after the. path handler handler. Each. endpoint is treated a. function as a reference to a. file with user controlled content anywhere (for example, using /collector/uploaded. an arbitrary shell.”]

Source: https://medium.com/realmodelabs/sd-pwn-part-2-citrix-sd-wan-center-another-network-takeover-a9c950a1a27c

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Thousands of Magento websites compromised to serve malware

News

Office 365 Secure Score: An Introduction