Security Basics mailing list archives

Re: Citrix Web Interface - VPN - public computer...secure??


From: infolookup () gmail com
Date: Thu, 10 Jul 2008 15:39:01 +0000

IMHO, it really matters who is logging in and what access rights the have, I would recommend look at a video 
presentation from this years Shmoocon on Citirix security.

If your over all network setup is secure and someone steals a set of login creds the most the can do is impersonate 
that user and try to gather information from the inside.

Level of severity to me depends on what the user/ attacker can come away with.
------Original Message------
From: Don Joly
Sender: listbounce () securityfocus com
To: security-basics () lists securityfocus com
Sent: Jul 9, 2008 11:17 PM
Subject: Citrix Web Interface - VPN - public computer...secure??


We have a Citrix Secure Gateway that some of our employees use for web VPN access from home. The Citrix Gateway 
provides users with published applications and desktops and has a valid SSL Cert. We have policies that all must sign 
agreeing to have some type of firewall enabled, OS patches and anti-virus software up to date. The policy also states 
that no user is to connect to the Citrix Gateway from a "public computer" or from a public hot spot. I've been asked if 
we could change this policy to allow connections from public computers and hot spots but I'm not sure how secure this 
would be. Would this be considered safe to allow this type of access? Why or why not?
 
Thanks,
Don



_________________________________________________________________
The i’m Talkaton. Can 30-days of conversation change the world?
http://www.imtalkathon.com/?source=EML_WLH_Talkathon_ChangeWorld

Sent from my Verizon Wireless BlackBerry

Current thread: