
CVE-2022-1388 | F5 - Big IP '/mgmt/tm/util/bash' 엔드포인트를 통한 사전 인증 RCE
CVE 2022-1388을 위한 익스플로잇 및 점검 스크립트
_____ _ _ _____ _____ _____ _____ _____ __ _____ _____ _____
/ __ \| | | || ___| / __ \| _ |/ __ \/ __ \ / | |____ || _ || _ |
| / \/| | | || |__ ______`' / /'| |/' |`' / /'`' / /'______`| | / / \ V / \ V /
| | | | | || __||______| / / | /| | / / / / |______|| | \ \ / _ \ / _ \
| \__/\ \_/ /| |___ ./ /___\ |_/ /./ /___./ /___ _| |_.___/ /| |_| || |_| |
\____/ \___/ \____/ \_____/ \___/ \_____/\_____/ \___/\____/ \_____ \_____/
CVE-2022-1388 F5 Exploit [ Valentin Lobstein ]
Usage:
Exploit Host: python3 CVE_2022_1388.py -u target_url -c command
Exploit List: python3 CVE_2022_1388.py -f file -c command
( Command is not required )
/mgmt/tm/util/bash을(를) 엔드포인트로 스캔하면 웹 서버 로그에 나타날 가능성이 높습니다. 또는 F5를 보유하고 있다면 패치하십시오. 영향을 받는 버전은 아래에 나와 있으며 패치는 여기 https://support.f5.com/csp/article/K23605346 에서 확인할 수 있습니다.
zoomeye search 'banner:"BIG-IP Configuration Utility"' -num 1000 -filter=ip,port
zoomeye search 'title:"BIG-IP®-+Redirect"+"Server"' -num 10 -filter=ip,port
shodan search 'http.html:"BIG-IP Configuration Utility"' --fields=ip_str,port --separator ":" --limit 10 | grep ''
shodan search 'http.title:"BIG-IP®-+Redirect"+"Server"' --fields=ip_str,port --separator ":" --limit 10 | grep ''