Dear oh _dear_, Citrix. The most retro -- no, the most *vintage* exploit I've seen for years.

https://github.com/assetnote/exploits/blob/main/citrix/CVE-2023-4966/exploit.py
#Shitrix

exploits/citrix/CVE-2023-4966/exploit.py at main · assetnote/exploits

Repository to store exploits created by Assetnotes Security Research team - assetnote/exploits

GitHub
Citrix Bleed: Leaking Session Tokens with CVE-2023-4966

It's time for another round Citrix Patch Diffing! Earlier this month Citrix released a security bulletin which mentioned "unauthenticated buffer-related vulnerabilities" and two CVEs. These issues affected Citrix NetScaler ADC and NetScaler Gateway.

Neuer Kunde. Diesmal mit c̶i̶t̶r̶i̶x̶ #shitrix workspace Umgebung. Ich hab noch nie so eine bekloppte Installation durchgeführt.
#mood
@sophie You had me at #Shitrix 😱
Anyone seeing #Shitrix #CVE202227510 exploitation yet?
@gossithedog  
ps. i need a distraction rn because im updating my #shitrix atm
CERT.at Citrix Gateway und Citrix ADC jetzt patchen

@gossithedog mainly VPN Gateways affected but ye.. btw i have to manage a Netscaler here lol
#Shitrix i love it!