|
In order to implement a full featured Web Interface login site, follow the following three steps.
Install Web Interface 2.1 (standalone web server only)
Configure Web Interface through the Web Interface 2.1 Administration Web pages
Brand the Web Interface login pages.
You will also want to make sure you follow the security recommendations for the particular Web Server that you are using.
Note: Web Interface 2.1 is a security update to the version of Web Interface release with MetaFrame XP Feature Release 3.
The issue was that when Web Interface 2.0 was reporting an authentication failure, includes the text of the error message in the URL. By constructing such a URL that contained script, if an attacker could lure the user into navigating to that URL, that script would be executed in the context of Web Interface, which is typically in the users Local Intranet or Trusted Sites zones; this script might then exploit other unrelated vulnerabilities in other client-side software.
You are able to download version 2.1 from the download section of MyCitrix.com.
|