This message was deleted.
# citrix-netscaler
s
This message was deleted.
d
I came across something similar last month, someone with a 12.1 appliance that was last patched in 2018 and had been compromised by the CVE from December 2019 (and still sitting there running but somehow they hadn't breached further into the network!) I just grabbed the config file and built them a new 13.1, only took me a couple of hours
a
The rebuild on 13.1 is my plan that I hope they agree to. I actually think they may have had an earlier exploit as sw mod dates on most files in ns_gui/vpn from March this year which seems odd given the firmware is from 2021. A new php file dropped in the and the index.html that had extra code to call js from a 3rd party site both have mod dates from Monday this week though and were the confirmation of breach and someone still doing something.
That is unless https://jscloud.biz was a valid site Citrix outsourced it's js to run from??? 😔
s
@Carl Behrent seems to be the hoarder of old netscaler versions. 😃 Any chance you have this one?
c
Unfortunately no sorry
n
I have a 12.1 55.18 OVF out on a file server, not sure if that's new enough to help. I do have a 61.19 image for KVM (qcow2 format) though.
a
No problems. The 12.1 VM is powered down and a fresh 13.1 instance will replace it once the customers investigation is done. Just to add a twist, while reviewing the files I pulled from the device I found evidence it had also been attacked for 4 days in the great Shitrix exploit of 2019/2020, but was luckily patched/cleaned at the time before any ransomware was dropped to the internal network. 😲