This message was deleted.
# citrix-netscaler
s
This message was deleted.
j
Re: the Behavioral checks, I'm seeing the below hit for the file search on page 2 on every Netscaler in my environment. Even one I just spun up today that had no network until a few minutes ago.
find / -type f -name "res*" | grep -E 'res($|\.[a-z]{3})$'
/var/python/lib/python2.7/site-packages/gevent-1.2.2-py2.7-freebsd-8.4-RELEASE-amd64.egg/gevent/resolver_ares.pyc
(spinning up a fresh one is a good way to get the known good hashes for
cd /netscaler ; for i in "nsppe nsaaad nsconf nsreadfile nsconmsg"; do md5 ${i} ; done
)
@Stu Carroll Any chance you whipped up a similar Powershell -> NitroAPI for the IOCs/MD5 hash checks akin to your CitrixADC-CVE-2020-8300.ps1 script?
s
this is for the recent CVE-2022-27518 or a new one?
j
NSA doc is for the one today
👍 2
s
Not something I’ve looked at yet but I know you can get the base64 content of a file on an appliance via the NITRO API so it would just be a case of comparing the base 64 of the binaries from the appliance against those in the firmware packages of the same version. One for the weekend maybe