Citrix Presentation Server allows remote users to work off a network server as if they weren't remote. That means: Incredibly fast access to data and applications for users, no third party VPN connection, and no latency issues. All of these features make Citrix Presentation Server a great tool for increasing access and productivity for remote users. Unfortunately, these same features make Citrix just as dangerous to the network it's running on. By definition, Citrix is granting remote users direct access to corporate servers?..achieving this type of access is also the holy grail for malicious hackers. To compromise a server running Citrix Presentation Server, a hacker need not penetrate a heavily defended corporate or government server. They can simply compromise the far more vulnerable laptop, remote office, or home office of any computer connected to that server by Citrix Presentation Server. All of this makes Citrix Presentation Server a high-value target for malicious hackers. And although it is a high-value target, Citrix Presentation Servers and remote workstations are often relatively easily hacked, because they are often times deployed by overworked system administrators who haven't even configured the most basic security features offered by Citrix. qThe problem, in other words, isn't a lack of options for securing Citrix instances; the problem is that administrators aren't using them.q (eWeek, October 2007). In support of this assertion Security researcher Petko D. Petkov, aka qpdpq, said in an Oct. 4 posting that his recent testing of Citrix gateways led him to qtonsq of qwide-openq Citrix instances, including 10 on government domains and four on military domains. * The most comprehensive book published for system administrators providing step-by-step instructions for a secure Citrix Presentation Server. * Special chapter by Security researcher Petko D. Petkov'aka qpdp detailing tactics used by malicious hackers to compromise Citrix Presentation Servers. * Companion Web site contains custom Citrix scripts for administrators to install, configure, and troubleshoot Citrix Presentation Server.A critical component of XenApp security is the security of the underlying operating system (OS) platforms on which the XenApp software runs. ... Extended Security Update Inventory Tool This tool is used to detect security bulletins not covered by the MBSA and future bulletins that ... This is the latest version of Systems Management Server (SMS) 2003. ... Office Update into a single location that enables you to choose automatic or manual delivery and installation of high- priority updates.
|Title||:||Securing Citrix XenApp Server in the Enterprise|
|Publisher||:||Syngress - 2008-08-08|