Nessus
[Top] [All Lists]

Re: NESSUS CRASHING CITRIX METAFRAME SERVERS

To: nessus@list.nessus.org
Subject: Re: NESSUS CRASHING CITRIX METAFRAME SERVERS
From: "George A. Theall" <theall@tenablesecurity.com>
Date: Wed, 14 Mar 2007 21:04:04 -0400
Delivered-to: sp-com-lists@consult.net
Delivered-to: nessus-list1@securepoint.com
Delivered-to: nessus@list.nessus.org
In-reply-to: <200703142337.l2ENbdsq027904@www.harkless.org>
List-archive: <http://mail.nessus.org/pipermail/nessus>
List-help: <mailto:nessus-request@list.nessus.org?subject=help>
List-id: Discussion of Nessus software <nessus.list.nessus.org>
List-post: <mailto:nessus@list.nessus.org>
List-subscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=subscribe>
List-unsubscribe: <http://mail.nessus.org/mailman/listinfo/nessus>, <mailto:nessus-request@list.nessus.org?subject=unsubscribe>
References: <200703142337.l2ENbdsq027904@www.harkless.org>
Sender: nessus-bounces@list.nessus.org
User-agent: Thunderbird 1.5.0.10 (X11/20070221)
On 03/14/07 19:37, Dan Harkless wrote:

I talked to John in private email and he says that he confirmed that
'Thorough tests' was causing his Citrix service DoS.  He also says the
problem didn't start occurring until they applied some recent (at the time)
Citrix patches.

Someone's reported this to Citrix, right?

However, I also heard from a member of a different security group at my
company who saw my post, and he says that they use 'Thorough tests' against
Citrix servers without issue.  That plus the fact that the IMA service
(which was getting stopped in John's caes) isn't exposed on the servers I'm
scanning (just the ICA service, 1494/tcp) indicates to me that it should be
safe to turn on 'Thorough tests'.

As you note, the port range is indeed a consideration when enabling thorough tests. Many of the service detection plugins by default probe only the well-known port(s) associated with that service. Enabling thorough tests will cause those plugins to probe any open port which is still marked as an unknown service. So if you know that the only service that doesn't handle invalid input well is the the ICA service on port 1494 (because, say, of testing in a lab), you should be able to enable thorough tests and stay clear of trouble as long as you omit 1494 from the port range.


George
--
theall@tenablesecurity.com
_______________________________________________
Nessus mailing list
Nessus@list.nessus.org
http://mail.nessus.org/mailman/listinfo/nessus

<Prev in Thread] Current Thread [Next in Thread>