
CVE-2020-5902のためのネットワーク検出パッケージ、F5 Networks, Inc BIG-IPデバイスに影響を与えるCVE10.0脆弱性です。
CVE-2020-5902(F5 Networks BIG-IP デバイスに影響を与える CVE10.0 の脆弱性)に対する Zeek 検出パッケージです。
デフォルトでは両方の通知が有効になっていますが、成功したエクスプロイトに関する通知だけを有効にしたい場合は、scripts/bigIPF5.zeek 内のオプションを True に変更できます(例:option only_monitor_for_successful_exploit: bool = T;)。
| 通知 | デフォルトで有効? | only_monitor_for_successful_exploit = T で無効化 |
|---|
| BIGIP_exploit_attempt | はい | はい |
| BIGIP_exploit_success | はい | いいえ |
通知には、HTTP リクエストヘッダーの最大 1500 バイトと URI 情報が含まれます。これにより、必ずしも pcap に戻る必要なく、インシデント対応とトリアージを迅速化できます。例:
#separator \x09 #set_separator , #empty_field (empty) #unset_field - #path notice #open 2020-07-27-16-57-12 #fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude #types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] interval string stringstring double double
1595831352.218935 C9EcoD1bu0ertt08bb 192.168.31.37 63034 192.168.1.3 80 - - - tcp CVE_2020_5902::BIGIP_exploit_attempt An attempt to exploit an F5 BIG-IP device via CVE-2020-5902 was detected using uri '/hsqldb;' , however the server responded with a code='404' reason='Not Found', indicating the exploit attempt failed. The HTTP request headers are '{\x0a\x09[1] = [original_name=User-Agent, name=USER-AGENT, value=Wget/1.20.3 (darwin19.0.0)],\x0a\x09[2] = [original_name=Accept, name=ACCEPT, value=*/*],\x0a\x09[3] = [original_name=Accept-Encoding, name=ACCEPT-ENCODING, value=identity],\x0a\x09[4] = [original_name=Host, name=HOST, value=192.168.1.3],\x0a\x09[5] = [original_name=Connection, name=CONNECTION, value=Keep-Alive]\x0a}'. Refer to https://support.f5.com/csp/article/K52145254 - 192.168.31.37 192.168.1.3 80 - - Notice::ACTION_LOG 3600.000000 - - - - -
zeek -Cr your.pcap scripts/__load__.zeek