Light

Episode #946 Quiz

Citrix Bleed
Date: 2023-10-31 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Citrix Bleed (CVE-2023-4966) affected Citrix NetScaler ADC/Gateway. Assetnote reverse engineered patched nsppe binaries with Ghidra/BinDiff and found an unauthenticated OpenID endpoint using snprintf safely, then wrongly reusing snprintf’s returned required length as the response size. This overread leaked adjacent RAM, including session tokens, enabling authentication bypass and mass exploitation.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: In the ADAMnetworks whitelist architecture described this episode, what is the role of the outbound firewall component called "Don't Talk to Strangers"?
Question 2: What exact mistake in the Citrix NetScaler code caused the Citrix Bleed information leak?
Question 3: According to Assetnote’s analysis, what attacker-controlled input actually let the response grow large enough to trigger the leak?
Question 4: What additional property of the NetScaler code made the Citrix Bleed attack practical once the length check was absent?
Question 5: What happened on Sunday in Steve’s SpinRite 6.1 work, according to the episode?
Cancel