
Este script explota la vulnerabilidad de ejecución remota de código en F5 BIG-IP TMUI (CVE-2023-46747). Permite a un atacante no autenticado ejecutar comandos arbitrarios en un sistema F5 BIG-IP vulnerable.
argparsebinasciijsonrandomrequeststimeurllib3Instala los módulos que falten usando pip:
pip install requests
Opciones de línea de comandos
python exploit.py -u <target_url> [-t <proxy_url>]
python exploit.py -u https://192.168.1.100:8443 -t http://127.0.0.1:8080
Parámetros
-u (Required) Target URL of the F5 BIG-IP TMUI system.
-t Proxy server (optional), e.g., http://127.0.0.1:8080.
Generate Credentials: Randomly generates a username and password.
User Creation: Attempts to create a new user on the target using a specially crafted request.
Token Retrieval: Logs in with the new user to obtain a session token.
Command Execution: Executes arbitrary commands via the token.
generatesth(num): Generates random alphanumeric strings of length num.
unauth_create_user(target, username, password, proxy): Creates a user on the target system.
get_token(target, user, passwd, proxy): Retrieves an authentication token for the created user.
exec_command(target, token, cmd, proxy): Executes arbitrary commands on the target system.
This script is intended for educational and research purposes only. Unauthorized use of this script against systems you do not own or have explicit permission to test is illegal and unethical.