HomeSecurityCitrix: Administrators must terminate NetScaler user sessions

Citrix: Administrators must terminate NetScaler user sessions

Citrix reminds administrators that they should take additional steps after patching their NetScaler appliances against the CVE-2023-4966 'Citrix Bleed' vulnerability to protect vulnerable devices from attacks.

See also: Recently fixed Citrix NetScaler bug was used as a zero-day

Citrix

In addition to applying the necessary security updates, it is also recommended to delete all previous user sessions and terminate all active ones. This is a critical step, as the attackers behind the Citrix Bleed exploit steal authentication credentials, allowing them to access compromised devices even after the updates are applied.

Citrix patched the bug in early October, but Mandiant revealed that it had been actively used as a zero-day since at least late August 2023.

Mandiant also warned that compromised NetScaler sessions persist even after remediation, allowing attackers to move laterally through the network or compromise other accounts depending on the permissions the compromised accounts.

If you are using any of the affected versions listed in the security bulletin, we recommend that you upgrade immediately by installing the updated versions. After upgrading, we recommend that you remove any active or persistent sessions ,” Citrix said today

See also: New critical Citrix ADC and Gateway flaw used as zero-day

This is the second time the company has warned customers to end all active and persistent sessions using the following commands:

  • kill icaconnection -all
  • kill rdp connection -all
  • kill pcoipConnection -all
  • kill aaa session -all
  • clear lb persistentSessions

Today, CISA and the FBI warned that the LockBit ransomware group is exploiting the Citrix Bleed security flaw in a joint update with the Multi-State Information Sharing & Analysis Center (MS-ISAC) and the Australian Cyber ​​Security Center (ACSC).

NetScaler

Authorities also shared breach indicators and detection methods to help experts prevent attacks by the ransomware group that encrypts files and demands ransom.

See also: Citrix NetScaler: Hackers steal credentials from its login pages

However, there are alternative methods to block hackers from targeting NetScaler. One of these methods is to use a firewall to filter incoming traffic and block unwanted connections. You can configure your firewall to allow only specific IP addresses or to block specific IP addresses that are known to be malicious.

Another way to block hackers is to use an IDS/IPS (Intrusion Detection/Prevention System). This system automatically detects and blocks malicious traffic and attacks. You can configure your IDS/IPS to recognize the characteristics of attacks targeting NetScaler and automatically block them.

Additionally, you can use a Web Application Firewall (WAF) to protect NetScaler from attacks. A WAF scans and filters incoming traffic at the application layer, identifying and blocking malicious actions. You can configure your WAF to block specific types of attacks that target NetScaler, such as SQL injection or Cross-Site Scripting (XSS) attacks.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS