4 ms·
What hasn't gotten enough attention here in my view is how astoundingly basic this exploit is. https://github.com/GossiTheDog/scanning/blob/main/CitrixBleed.cu
by technion 3y ago
What hasn't gotten enough attention here in my view is how astoundingly basic this exploit is.
https://github.com/GossiTheDog/scanning/blob/main/CitrixBleed.curl https://github.com/GossiTheDog/scanning/blob/main/CitrixBlee...
You've got a single curl request to a web service that for magical reasons is running as root. There's no SELinux/jails/etc, and no logs written for this request.
Remember this next time someone wants to sell you a WAF: The Netscaler isn't some wiki application, one of the things it is sold for is specifically as a WAF.