
Эксплойт-скрипт для CVE-2023-46747 (F5 BIG-IP TMUI RCE), позволяющий неаутентифицированное создание пользователей, получение токенов и удаленное выполнение команд на уязвимых системах.
Этот скрипт эксплуатирует уязвимость удалённого выполнения кода F5 BIG-IP TMUI (CVE-2023-46747). Он позволяет неаутентифицированному злоумышленнику выполнять произвольные команды на уязвимой системе F5 BIG-IP.
argparsebinasciijsonrandomrequeststimeurllib3Установите недостающие модули с помощью pip:
pip install requests
Параметры командной строки
python exploit.py -u <target_url> [-t <proxy_url>]
python exploit.py -u https://192.168.1.100:8443 -t http://127.0.0.1:8080
Параметры
-u (Required) Target URL of the F5 BIG-IP TMUI system.
-t Proxy server (optional), e.g., http://127.0.0.1:8080.
Generate Credentials: Randomly generates a username and password.
User Creation: Attempts to create a new user on the target using a specially crafted request.
Token Retrieval: Logs in with the new user to obtain a session token.
Command Execution: Executes arbitrary commands via the token.
generatesth(num): Generates random alphanumeric strings of length num.
unauth_create_user(target, username, password, proxy): Creates a user on the target system.
get_token(target, user, passwd, proxy): Retrieves an authentication token for the created user.
exec_command(target, token, cmd, proxy): Executes arbitrary commands on the target system.
This script is intended for educational and research purposes only. Unauthorized use of this script against systems you do not own or have explicit permission to test is illegal and unethical.