this post was submitted on 13 Sep 2024
43 points (100.0% liked)

Cybersecurity

5396 readers
83 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] superkret@feddit.org 10 points 4 days ago (2 children)

We've been dealing with this shit for the past 3 days.
How the fuck do you even create a security hole that lets unprivileged users accessing a client app get SYSTEM rights to the server?
Didn't even know that was technically possible even if you tried to program it.

Oh well, at least we'll have an up-to-date client device inventory and no more BYOD shenanigans at the end of it.

[–] CaptObvious@literature.cafe 6 points 4 days ago (2 children)

Judging from recent forum posts, Citrix still installs a hidden server running with privileged access as part of their client software. It's almost impossible for normal users to remove it.

Wasn't this the same behavior that got Zoom blocked briefly on macOS a few years ago? https://www.macobserver.com/news/apple-update-remove-zoom/

[–] superkret@feddit.org 5 points 4 days ago* (last edited 4 days ago)

I wish we could get rid of Citrix yesterday, but:

  1. We've got our hands full till next year with a physical relocation of the business, migration to M365, replacement of all servers and storage, and getting the fuck away from VMWare
  2. I was technically hired as a Citrix Admin (despite never having heard of the software before), so replacing it might put my job in jeopardy.
[–] Zorsith@lemmy.blahaj.zone 1 points 4 days ago* (last edited 4 days ago)

Got any links about the hidden server aspect of Citrix? I'd love to read more (I'd google it but these days Google is just... gestures vaguely

[–] mp3@lemmy.ca 6 points 4 days ago (2 children)

security hole that lets unprivileged users accessing a client app get SYSTEM rights to the server

wtf 🤣

[–] superkret@feddit.org 4 points 4 days ago

That was my reaction, but with even more tears and less laughing.

[–] Maeve@kbin.earth 2 points 4 days ago

Kind of explains a lot.