https://worldofeuc.com logo
Join Slack
Powered by
# citrix-netscaler
  • t

    Thomas Poppelgaard

    10/02/2026, 9:49 PM
    any seen this cyberplace.social/@GossiTheDog/117372857146978531
    👀 1
  • m

    Mike Gray

    10/02/2026, 10:11 PM
    What is the over/under on a patch this weekend do we think?
  • m

    Melissa Nelson

    10/02/2026, 10:16 PM
    What if I just want to block all saml requests since we don’t use it. Responder policy?
    c
    • 2
    • 3
  • l

    langsbr

    10/03/2026, 1:50 AM
    I have my money on a patch tomorrow
  • s

    steven.shine

    10/03/2026, 3:38 AM
    I'm currently blocking IPs at the NetScalers. Our networking team is also blocking them at the edge firewalls. are the gotham tech group mitigations effective or recommended? we've just opened a case with citrix
    d
    • 2
    • 1
  • c

    Christian Jöns

    10/03/2026, 3:57 AM
    Okay for now. What works well when it comes to the SAML issue? There's so much discussion in this channel about this topic. 🙈
    n
    d
    +2
    • 5
    • 18
  • k

    Kari Ruissalo (WyW)

    10/03/2026, 4:39 AM
    Regardless of the Responder policy, we're seeing reboots, adding ACL to block the source IP 213.209.159.55
    🙌 1
    • 1
    • 1
  • s

    steven.shine

    10/03/2026, 5:28 AM
    is citrix gateway as a service impacted?
    d
    d
    j
    • 4
    • 3
  • a

    Arthur

    10/03/2026, 7:45 AM
    To summarize what’s the best working solution?
    d
    c
    +5
    • 8
    • 10
  • m

    Marius Sandbu

    10/03/2026, 12:23 PM
    Has anyone seen any other indication then DoS ( restart ? ) so much wierd stuff being posted on other social media channels and security vendors spamming with their own IoC and trying to sell products that is rotting my brain.
    c
    d
    t
    • 4
    • 10
  • t

    Thomas Poppelgaard

    10/03/2026, 1:00 PM
    did a HUGE clean up of my doom blogpost about the netscaler CVE poppelgaard.com/cve-2026-88771-through-cve-2026-88778-what-you-should-know-and-how-to-fix-your-netscaler-adc-netscaler-gateway#… you can now just click one thing you want to read about and move on... s orry for wasting peoples life doomscrolling.. i do better in future 😄
    👍 3
    🙏 1
  • t

    Thomas Poppelgaard

    10/03/2026, 1:01 PM
    github updated with version 1.11 github.com/ThomasPoppelgaard/netscaler-ctx697096-checker release notes: github.com/ThomasPoppelgaard/netscaler-ctx697096-checker/…/1.11 #FEEDBACK appreaciated so we can win this 😉
  • c

    Charles Moore

    10/03/2026, 1:59 PM
    FYI: Seeing new injection attack from : 89.44.80.7 (HZ Hosting, Bulgaria) - 22, 031 failures since 5:38 UTC. See base64 chunks in the username field followed by fake pitboss crash messages.
  • m

    Marius Sandbu

    10/03/2026, 2:05 PM
    Against SAML vserver?
  • j

    Jason Symczak

    10/03/2026, 2:18 PM
    seeing the same, have the find the IP
  • j

    Jason Symczak

    10/03/2026, 2:18 PM
    @Charles Moore are your messages like this?
  • j

    Jason Symczak

    10/03/2026, 2:19 PM
    image.png
  • c

    Charles Moore

    10/03/2026, 2:19 PM
    yes, against my SAML servers, since I posted that I did see that that IP is Thomas's github site's list.
  • j

    Jason Symczak

    10/03/2026, 2:21 PM
    how do do I search for the source IP of that attack in splunk?
  • c

    Charles Moore

    10/03/2026, 2:22 PM
    Copy code
    not using splunk, but yes, thats an exact match: 
    AAA LOGIN_FAILED ... User pitboss PPE unexpectedly died NSPPE;<command>;# X (the main one, 61,295 lines on 01-cvg since 2 October per the checker)
    AAA Message ... "Authentication is rejected for pitboss PPE unexpectedly died NSPPE;<command>..."
    AAATM Message ... "AAAD RESP: received resp, user: <pitboss PPE unexpectedly died NSPPE;<command>;# X>, factor: <aaavsrv_...>"
  • j

    Jason Symczak

    10/03/2026, 2:23 PM
    image.png
  • j

    Jason Symczak

    10/03/2026, 2:23 PM
    would that 46.151.182.18 be an ip from the attacker?
  • j

    Jason Symczak

    10/03/2026, 2:25 PM
    definately looks like it...
  • c

    Charles Moore

    10/03/2026, 2:27 PM
    yes, thats the attackers IP
  • c

    Charles Moore

    10/03/2026, 2:27 PM
    I see the same IP
  • j

    Jason Symczak

    10/03/2026, 2:28 PM
    132.243.166.140 is another one
    r
    • 2
    • 1
  • c

    Charles Moore

    10/03/2026, 2:29 PM
    same
  • c

    Charles Moore

    10/03/2026, 3:06 PM
    new responder policy that Citrix supplied applies to all vservers not just vservers using saml. fun, I guess because all endpoints have those url paths even if saml is not configured.
    e
    • 2
    • 1
  • j

    Jason Symczak

    10/03/2026, 3:17 PM
    can you share it?
  • k

    Kari Ruissalo (WyW)

    10/03/2026, 3:42 PM
    just got update from v5c to v5d, I'm thinking of creating an expression that holds the stuff given by support when the version changes and then just have the same responder policy always bound on all relevant objects... then we can just do set expression command and use the same "samlshit" regardless of the environment, it would be easier to manage