Skip to main content

Alert: Actors exploiting Citrix products vulnerability

An NCSC alert detailing the investigation into the exploitation of a critical vulnerability in Citrix products.

Update note

This Alert is an updated version of the Alert published on 14 January 2020.

It provides updated information on another product (SD-WAN WANOP) also affected by the vulnerability, newly released fixes and creation of an IoC scanning tool to detect exploitation.






title: Citrix Netscaler Attack CVE-2019-19781
description: Detects CVE-2019-19781 exploitation attempt against Citrix Netscaler, Application Delivery Controller and Citrix Gateway Attack
id: ac5a6409-8c89-44c2-8d64-668c29a2d756
references:

  • https://support.citrix.com/article/CTX267679#
  • https://support.citrix.com/article/CTX267027
  • https://isc.sans.edu/diary/25686
  • https://twitter.com/mpgn_x64/status/1216787131210829826

author: Arnim Rupp, Florian Roth
status: experimental
date: 2020/01/02
modified: 2020/01/13
logsource:
category: webserver
description: 'Make sure that your Netscaler appliance logs all kinds of attacks (test with http://your-citrix-gw.net/robots.txt)'
detection:
selection:
c-uri-path:

  • '*/../vpns/*'
  • '*/vpns/cfg/smb.conf'
  • '*/vpns/portal/scripts/newbm.pl*'
  • '*/vpns/portal/scripts/rmbm.pl*'
  • '*/vpns/portal/scripts/picktheme.pl*'

condition: selection
fields:

  • client_ip
  • vhost
  • url
  • response

falsepositives:

  • Unknown

level: critical

In addition, the following Snort rule alerts on the first part of the "Project Zero India" exploit:

alert tcp any any -> any any (sid: 1019781; msg: "SERVER-WEBAPP Citrix ADC NSC_USER directory traversal attempt"; content: "NSC_USER:"; fast_pattern; content: "NSC_USER:"; http_header; content: "/../"; http_header; content: "POST"; http_method; content: "NSC_NONCE:" ; http_header; content: ".pl"; http_uri; content: "/vpns/"; http_uri; reference:cve,2019-19781; classtype: web-application-attack)

Exploitation code is also available via the links below: