<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.brianmadden.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hans Straat - All Comments</title><link>http://www.brianmadden.com/blogs/hans_straat/default.aspx</link><description>Hans Straat is the founder of Datacrash.net, a news feed and blog that also offers a server based computing forum, white papers, and other technical resources. Hans is a MCSE in Windows NT4, 2000, and 2003, in addition to specializing in Citrix.</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 (Build: 30929.2835)</generator><item><title>user is stil the biggest security risk</title><link>http://www.brianmadden.com/blogs/hans_straat/archive/2007/10/11/security-researcher-warns-about-citrix-vulnerability.aspx#728</link><pubDate>Tue, 16 Oct 2007 12:01:23 GMT</pubDate><guid isPermaLink="false">a59ee4a9-9560-4436-b47c-b649e4ba6aaa:728</guid><dc:creator>hans straat</dc:creator><description>Like said in my comments on the article and on the dutch site tweakers.net the biggest risk is still the user. This is not a bug but they simply use the ICA client to gain access to an environment. You still need user credentials to logon to such an environment and most environments don't have ftp or tftp open only port 80 for internet browsing. &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.brianmadden.com/aggbug.aspx?PostID=728" width="1" height="1"&gt;</description></item><item><title>Re: Re: The details are sketchy</title><link>http://www.brianmadden.com/blogs/hans_straat/archive/2007/10/11/security-researcher-warns-about-citrix-vulnerability.aspx#727</link><pubDate>Fri, 12 Oct 2007 19:42:08 GMT</pubDate><guid isPermaLink="false">a59ee4a9-9560-4436-b47c-b649e4ba6aaa:727</guid><dc:creator>Guest</dc:creator><description>The sad thing is that a manager level will read this article and immediatly panic thinking that their Citrix environment is not secure.  Anyone with any network savy will see that this is not a Citrix issue.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.brianmadden.com/aggbug.aspx?PostID=727" width="1" height="1"&gt;</description></item><item><title>Re: The details are sketchy</title><link>http://www.brianmadden.com/blogs/hans_straat/archive/2007/10/11/security-researcher-warns-about-citrix-vulnerability.aspx#726</link><pubDate>Fri, 12 Oct 2007 02:30:31 GMT</pubDate><guid isPermaLink="false">a59ee4a9-9560-4436-b47c-b649e4ba6aaa:726</guid><dc:creator>Guest</dc:creator><description>Have to agree, that looks more like someone who doesn't know what they are doing at implementation rather than technical problems with Citrix. &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.brianmadden.com/aggbug.aspx?PostID=726" width="1" height="1"&gt;</description></item><item><title>The details are sketchy</title><link>http://www.brianmadden.com/blogs/hans_straat/archive/2007/10/11/security-researcher-warns-about-citrix-vulnerability.aspx#725</link><pubDate>Fri, 12 Oct 2007 01:53:53 GMT</pubDate><guid isPermaLink="false">a59ee4a9-9560-4436-b47c-b649e4ba6aaa:725</guid><dc:creator>Guest</dc:creator><description>This article was also posted in eWeek - but if you look at the detail you will see that the problem is a CPS server sitting directly on the internet with no security.  More of an imprementation issue than a CPS issue.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.brianmadden.com/aggbug.aspx?PostID=725" width="1" height="1"&gt;</description></item></channel></rss>