Going outside Citrix context

No ratings

Presented at HackLu 2008 by

Citrix is a Remote Desktop application that is very popular and is often used between a company and an affiliate. It is similar to Microsoft's Terminal Services, RDP (Remote Desktop Protocol).Microsoft Terminal Services uses RDP, whereas Citrix uses ICA (Independent Computing Architecture). Unlike Terminal Services, the Citrix products allow the administrator to specify certain applications to be run on the server in a restricted mode. This allows them to control which programs they want to allow the end user to execute. In fact the restriction can be bypassed and a remote desktop can be obtained. This presentation will show how it's possible to go outside the citrix context by abusing of Microsofts' products features Since 2001, Joffrey is pentester, he has released advisories on VoIP Cisco products and spoken at various security-focused conferences (Wireless Conference at Infosec Paris and Wireless Workshop at Hack.lu 2005, VoIP af Hack.lu 2007 and ITunderground 2008).On his site, www.insomnihack.net, he maintains Elsenot project ("http://insomnihack.net/elsenot/")and posts video tutorials and tools on security aspect. Since 2001, Joffrey is pen-tester for the Security Research Centre of Telindus He also spoke at security-focused conferences (Wireless Conference at Infosec Paris and Wireless Workshop at Hack.lu 2005, VoIP af Hack.lu 2007 and ITunderground 2008)