Cybersecurity
January 16, 2020

Codename Shitrix: attackers scramble to exploit CVE-2019-19781

a padlock on a laptop keyboardlong exposure image of man walking by blue panels

US-based software firm Citrix last month released an advisory for a vulnerability that existed in Citrix Application Delivery Controller and Citrix Gateway installations. Exploit code for the vuln (CVE-2019-19781) was released to the public on 10th January, at which time there was no official patch.

This is concerning for a company that was brutally attacked by hackers last year, with swathes of its customer data exposed online. Resecurity attributed that attack to Iranian-linked hacker group IRIDIUM – and if that interests you, our full breakdown of Iran’s cyber capability is available here.

Research groups have now posted proof-of-concept (POC) exploit code for the recent vuln on GitHub, so Citrix’s mitigatory advice should be actioned by all affected organizations. Project Zero India released one exploit for the remotely executable flaw, while the other – dubbed Citrixmash – comes via security consulting firm TrustedSec.

And there are also reports suggesting that scanning activity has surged in recent days, which means it’s likely that attackers are now seeking systems to exploit.

At Immersive Labs we’ve created both red and blue team labs on Shitrix, so you can learn how to mitigate the vulnerability while also thinking like the bad guys. Check out our overview of the two labs below.

Blue Team lab

In this lab you will explore investigative techniques post-compromise by analyzing network traffic, identifying C2 commands and creating a Snort rule to detect future attacks.

Red Team lab

In this lab you will use the proof-of-concept code to exploit a vulnerable server and escalate your privileges to root.

Trusted by top companies worldwide
to enhance cybersecurity

Trusted by some of the world’s biggest brands, we’re committed to taking your cybersecurity readiness to the next level - and we’re just getting started.

What Our Customers
Are Saying About Immersive

Realistic simulation of current threats is the only way to test and improve response readiness, and to ensure that the impact of a real attack is minimized. Immersive’s innovative platform, combined with Kroll’s extensive experience, provides the closest thing to replication of a real incident — all within a safe virtual environment.

Paul Jackson
Regional Managing Director, APAC Cyber Risk, Kroll

The speed at which Immersive produces technical content is hugely impressive, and this turnaround has helped get our teams ahead of the curve, giving them hands-on experience with serious vulnerabilities, in a secure environment, as soon as they emerge.

TJ Campana
Head of Global Cybersecurity Operations, HSBC

We no longer worry about managing infrastructure, leaving us free to build great courses.

Daniel Duggan
Director, Zero-Point Security

Ready to Get Started?
Get a Live Demo.

Simply complete the form to schedule time with an expert that works best for your calendar.