WEBVTT

1
00:00:03.200 --> 00:00:07.680
This is Decrypted. Wednesday, the thirtieth of September.

2
00:00:07.680 --> 00:00:13.280
Citrix has patched NetScaler, but a patch will not remove the web shell.

3
00:00:13.280 --> 00:00:17.440
The NetScaler story we covered on Sunday has moved.

4
00:00:17.440 --> 00:00:21.600
Citrix has now published patches for its two zero-days.

5
00:00:21.600 --> 00:00:24.640
The N C S C has issued an alert.

6
00:00:24.640 --> 00:00:31.200
And Mandiant and Google Threat Intelligence Group have described what attackers left behind on compromised ap

7
00:00:31.200 --> 00:00:35.360
pliances. The advice is no longer just "patch".

8
00:00:35.360 --> 00:00:39.760
It's "patch, then check whether someone was already inside".

9
00:00:39.760 --> 00:00:51.170
Next.

What has changed.

Citrix's bulletin covers eight vulnerabilities in NetScaler A D C and NetScaler Ga

10
00:00:51.170 --> 00:00:53.840
teway. Two of them are being exploited.

11
00:00:53.840 --> 00:01:01.520
C V E twenty twenty-six, eight eight seven seven one lets an unauthenticated attacker run commands.

12
00:01:01.520 --> 00:01:09.933
C V E twenty twenty-six, eight eight seven seven two is a memory overflow that can give code execution, or a

13
00:01:09.933 --> 00:01:12.440
crash, when D T L S is enabled.

14
00:01:12.440 --> 00:01:16.400
The N C S C alert is dated 28 September.

15
00:01:16.400 --> 00:01:19.280
It says affected builds are 14.

16
00:01:19.280 --> 00:01:24.480
1 before 14.1-73.37, and 13.

17
00:01:24.480 --> 00:01:34.104
1 before 13.1-64.23.

Mandiant says attacks on organisations in North America and Europe began in early Septem

18
00:01:34.104 --> 00:01:36.800
ber. That's well before any patch existed.

19
00:01:36.800 --> 00:01:39.760
Counts of exposed appliances differ.

20
00:01:39.760 --> 00:01:45.920
Censys reported 42,735 vulnerable hosts.

21
00:01:45.920 --> 00:01:49.000
Palo Alto Networks put it above 50,000.

22
00:01:49.000 --> 00:01:53.480
And also.

How the break-in works.

23
00:01:53.480 --> 00:02:00.400
Think of a post room clerk who has to open every parcel at the door, before checking who sent it.

24
00:02:00.400 --> 00:02:07.360
Mandiant assesses that malformed D T L S record headers corrupt memory inside the appliance's packet engine.

25
00:02:07.360 --> 00:02:12.000
D T L S is a way of encrypting traffic over U D P.

26
00:02:12.000 --> 00:02:16.720
The attacker's parcel is folded so the spillage lands as instructions.

27
00:02:16.720 --> 00:02:21.360
Those instructions then run as root on the underlying FreeBSD system.

28
00:02:21.360 --> 00:02:24.160
No password is involved at any point.

29
00:02:24.160 --> 00:02:28.480
Once inside, the attackers install a web shell called WHIPSHOT.

30
00:02:28.480 --> 00:02:31.280
It's disguised as a Debian package file.

31
00:02:31.280 --> 00:02:36.880
It takes commands hidden in H T T P headers, and it always answers with a 404.

32
00:02:36.880 --> 00:02:40.213
So a casual glance at the logs shows nothing.

33
00:02:40.213 --> 00:02:43.820
They also edit the web server configuration, so that.

34
00:02:43.820 --> 00:02:46.000
deb files are handled as P H P.

35
00:02:46.000 --> 00:02:51.121
A second tool, SLAPSHOT, is a small Python proxy.

36
00:02:51.121 --> 00:02:54.721
It opens a port and forwards traffic into the internal network.

37
00:02:54.721 --> 00:02:57.201
That's where credential theft begins.

38
00:02:57.201 --> 00:03:01.841
And also.

What a defender sees.

39
00:03:01.841 --> 00:03:07.101
Very little.

Published indicators include P H P handlers for.

40
00:03:07.101 --> 00:03:14.321
deb files in httpd.conf, and the setuid bit set on /bin/sh.

41
00:03:14.321 --> 00:03:21.841
Also look for.deb or.sig files that contain P H P, and a file named /tmp/.

42
00:03:21.841 --> 00:03:26.321
uxdport.

Patching doesn't remove a web shell that's already there.

43
00:03:26.321 --> 00:03:33.788
That's why the N C S C says, if possible, to isolate the affected system and replace it with a new, fully up-

44
00:03:33.788 --> 00:03:37.361
to-date one. It notes this may cause an outage.

45
00:03:37.361 --> 00:03:40.001
That's a rebuild, not a patch window.

46
00:03:40.001 --> 00:03:50.241
Disabling D T L S and blocking inbound U D P/443 closes the C V E twenty twenty-six, eight eight seven seven

47
00:03:50.241 --> 00:03:57.201
two route. But it doesn't protect you against C V E twenty twenty-six, eight eight seven seven one.

48
00:03:57.201 --> 00:04:02.281
And finally.

The Secure by Design lesson.

49
00:04:02.281 --> 00:04:10.034
Here's the pattern. An internet-facing gateway parses hostile input before authentication, and runs as root

50
00:04:10.034 --> 00:04:14.482
when it does. That turns one memory bug into total control.

51
00:04:14.482 --> 00:04:23.346
CyberScoop reports that Citrix has appeared on Sisa's exploited list five times in 2026, and 26 times since

52
00:04:23.346 --> 00:04:31.542
late 2021. It also reports that the company stayed publicly silent for more than 36 hours after exploitation r

53
00:04:31.542 --> 00:04:38.242
umours began. Coalition's Joe Toomey called that silence "unconscionably irresponsible".

54
00:04:38.242 --> 00:04:41.122
You can't redesign the vendor's code.

55
00:04:41.122 --> 00:04:43.202
But you can design around it.

56
00:04:43.202 --> 00:04:47.762
Know which edge devices you run, and who receives their advisories.

57
00:04:47.762 --> 00:04:52.722
Keep a known-good configuration, so a rebuild takes hours, not days.

58
00:04:52.722 --> 00:04:55.602
Put logging somewhere the appliance can't rewrite.

59
00:04:55.602 --> 00:05:01.922
And ask suppliers, at renewal, whether their pre-authentication code is isolated and unprivileged.

60
00:05:01.922 --> 00:05:07.042
That was Decrypted. The written version and every source are linked in the show notes.

61
00:05:07.042 --> 00:05:08.482
Thanks for listening.

