
نص استغلال لـ CVE-2023-46747 (F5 BIG-IP TMUI RCE) يتيح إنشاء مستخدم غير مصادق عليه واسترجاع الرمز وتنفيذ الأوامر عن بُعد على الأنظمة الضعيفة.
يستغل هذا السكربت ثغرة تنفيذ التعليمات البرمجية عن بُعد في F5 BIG-IP TMUI (CVE-2023-46747). وهو يسمح لمهاجم غير مصادَق بتنفيذ أوامر عشوائية على نظام F5 BIG-IP المعرض للثغرة.
argparsebinasciijsonrandomrequeststimeurllib3ثبّت الوحدات المفقودة باستخدام pip:
pip install requests
خيارات سطر الأوامر
python exploit.py -u <target_url> [-t <proxy_url>]
python exploit.py -u https://192.168.1.100:8443 -t http://127.0.0.1:8080
المعلمات
-u (Required) Target URL of the F5 BIG-IP TMUI system.
-t Proxy server (optional), e.g., http://127.0.0.1:8080.
Generate Credentials: Randomly generates a username and password.
User Creation: Attempts to create a new user on the target using a specially crafted request.
Token Retrieval: Logs in with the new user to obtain a session token.
Command Execution: Executes arbitrary commands via the token.
generatesth(num): Generates random alphanumeric strings of length num.
unauth_create_user(target, username, password, proxy): Creates a user on the target system.
get_token(target, user, passwd, proxy): Retrieves an authentication token for the created user.
exec_command(target, token, cmd, proxy): Executes arbitrary commands on the target system.
This script is intended for educational and research purposes only. Unauthorized use of this script against systems you do not own or have explicit permission to test is illegal and unethical.