Citrix NetScaler directory traversal attempts targeting /vpns/ portal scripts and config files
Flags suspicious NetScaler HTTP URIs containing traversal-style /vpns/ portal script or config file references.
FreeUnreviewedSigmacriticalv1
citrix-netscaler-directory-traversal-attempts-targeting-vpns-portal-scripts-and--ac5a6409
title: Citrix NetScaler directory traversal attempts targeting /vpns/ portal scripts and config files
id: 263c5ba3-be3e-477a-8525-219ab2e3317b
status: test
description: This rule identifies HTTP requests to Citrix NetScaler that look like path traversal or crafted URI attempts aimed at /vpns/ resources, including portal script paths ending in .pl and a specific smb.conf file. Attackers may use these requests to reach sensitive configuration files or execute/abuse web-accessible script endpoints exposed through traversal. The detection relies on webserver logs capturing the HTTP request URI query and matches specific /vpns/ path patterns and script-like resource paths.
references:
- https://support.citrix.com/article/CTX267679
- https://support.citrix.com/article/CTX267027
- https://isc.sans.edu/diary/25686
- https://twitter.com/mpgn_x64/status/1216787131210829826
- https://github.com/x1sec/CVE-2019-19781/blob/25f7ab97275b2d41800bb3414dac8ca3a78af7e5/CVE-2019-19781-DFIR.md
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2019/Exploits/CVE-2019-19781/web_cve_2019_19781_citrix_exploit.yml
author: Arnim Rupp, Florian Roth, Huntrule Team
date: 2020-01-02
modified: 2023-01-02
tags:
- attack.initial-access
- attack.t1190
- cve.2019-19781
- detection.emerging-threats
logsource:
category: webserver
definition: Make sure that your Netscaler appliance logs all kinds of attacks (test with http://your-citrix-gw.net/robots.txt). The directory traversal with ../ might not be needed on certain cloud instances or for authenticated users, so we also check for direct paths. All scripts in portal/scripts are exploitable except logout.pl.
detection:
selection_cs:
- cs-uri-query|contains: /../vpns/
- cs-uri-query|endswith: /vpns/cfg/smb.conf
selection_csall:
cs-uri-query|contains|all:
- /vpns/portal/scripts/
- .pl
condition: 1 of selection_*
falsepositives:
- Unknown
level: critical
license: DRL-1.1
related:
- id: ac5a6409-8c89-44c2-8d64-668c29a2d756
type: derived
What it detects
This rule identifies HTTP requests to Citrix NetScaler that look like path traversal or crafted URI attempts aimed at /vpns/ resources, including portal script paths ending in .pl and a specific smb.conf file. Attackers may use these requests to reach sensitive configuration files or execute/abuse web-accessible script endpoints exposed through traversal. The detection relies on webserver logs capturing the HTTP request URI query and matches specific /vpns/ path patterns and script-like resource paths.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.