Securing Citrix XenApp Server in the Enterprise

£38.99

Securing Citrix XenApp Server in the Enterprise

Operational research Computer security

Author: Tariq Azad

Dinosaur mascot

Language: English

Published by: Syngress

Published on: 8th August 2008

Format: LCP-protected ePub

Size: 10 Mb

ISBN: 9780080569987


Citrix Presentation Server Overview

Citrix Presentation Server allows remote users to work off a network server as if they weren't remote. That means: Incredibly fast access to data and applications for users, no third party VPN connection, and no latency issues. All of these features make Citrix Presentation Server a great tool for increasing access and productivity for remote users.

Security Concerns

Unfortunately, these same features make Citrix just as dangerous to the network it's running on. By definition, Citrix is granting remote users direct access to corporate servers?..achieving this type of access is also the holy grail for malicious hackers. To compromise a server running Citrix Presentation Server, a hacker need not penetrate a heavily defended corporate or government server. They can simply compromise the far more vulnerable laptop, remote office, or home office of any computer connected to that server by Citrix Presentation Server. All of this makes Citrix Presentation Server a high-value target for malicious hackers.

And although it is a high-value target, Citrix Presentation Servers and remote workstations are often relatively easily hacked, because they are often times deployed by overworked system administrators who haven't even configured the most basic security features offered by Citrix. "The problem, in other words, isn’t a lack of options for securing Citrix instances; the problem is that administrators aren’t using them." (eWeek, October 2007).

Recent Findings and Resources

In support of this assertion, security researcher Petko D. Petkov, aka "pdp", said in an Oct. 4 posting that his recent testing of Citrix gateways led him to "tons" of "wide-open" Citrix instances, including 10 on government domains and four on military domains.

- The most comprehensive book published for system administrators providing step-by-step instructions for a secure Citrix Presentation Server

- Special chapter by security researcher Petko D. Petkov aka "pdp" detailing tactics used by malicious hackers to compromise Citrix Presentation Servers

- Companion website contains custom Citrix scripts for administrators to install, configure, and troubleshoot Citrix Presentation Server

Show moreShow less