Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Citrix modifyable .ica files

Status
Not open for further replies.

heh

Technical User
Aug 20, 2002
4
US
lo folks,
I'm doing a security assessment for a company who is running citrix metaframe XP on 3 servers. All of the employee's may use specific 'published applications' such as access 2000/word office what have you. I'm by no means a Citrix Ninja but I have a pretty good understanding of how it works. Now... During my assessment I downloaded an ICA file and modified the [ProgramName] to cmd.exe (I could have also done explorer.exe but I decided to run explorer from cmd.exe). Anyways, So I modify the ica client file locally, then click it, login as a user which I've compromised.... now here comes my mis-understanding, and I may need to ask the client again. But, I maybe loggging in with someone who has 'desktop' access but I highly doubt it. So my question is, can any of these users modify the ICA client files to execute whatever application they want on the remote host? Only 3 users that I'm aware of actually have 'Desktop' rights (all administrators). So Any help would be appreciated I'm rather unsure how to approach the client at this point. Thank you for your time,
-heh

PS. If you think about this, this is pretty scary, any user, or a user you would only want executing certian applications can run explorer? or cmd? Talk about 'insta-server-root.' Lets hope I am mistaken some where....
 
Once the ica file has been downloaded to the client it is open to be edited by a knowledgeable user.

However, if the user does not have permission to use the app then it makes no odds really. You can lock down server executables via Group Policy.

Hope this helps CitrixEngineer@yahoo.co.uk
 
Group Policy via Windows Policy? Yikes that sounds... like an elaborate solution. So I have to add every single file that may be used malicously to gain control of the server? Thats quite a bit of work for 3-4 servers (Just in this scenario!). If there is a Group Policy in Citrix MetaFrame that you're discussing then its just my naivity to this product. I just can't imagine an administrator doing this for every server via Windows Policy Editor... Oh well I shall report this suggested solution regardless,
Thanks again.
-heh

PS. I was talking over with a friend and they mentiond 'Nfuse' as another possible alternative. Using nfuse published applications, the users would not be able to modify or download any of the 'connection' based information. I will also discuss this solution.
 
I don't mean a MetaFrame alternative - Group Policy is the AD replacement for poledit. It does pretty much the same thing. You explicity name the programs that can be run, rather than having to list all the ones that can't - so it's not that much effort!

You don't need NFuse to run published apps, although it's fast becoming my favoured way of giving Citrix access to clients. NFuse still needs to download what are tantamount to clear text files containing app information - but they're much more of a challenge for your average power user.

Hope this helps CitrixEngineer@yahoo.co.uk
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top