Sploitus

Exploit for Missing Authentication for Critical Function in F5 Big-Ip Access Policy Manager

githubexploit · 2024-02-11

Exploit Code

README77 lines
## https://sploitus.com/exploit?id=FCCB9444-9258-5043-85C0-6C43C1934D96
# CVE-2023-46747 Exploit Script

This script exploits the **F5 BIG-IP TMUI remote code execution vulnerability (CVE-2023-46747)**. It allows an unauthenticated attacker to execute arbitrary commands on a vulnerable F5 BIG-IP system.

---

## Table of Contents

- [Features](#features)
- [Requirements](#requirements)
- [Usage](#usage)
- [Parameters](#parameters)
- [How It Works](#how-it-works)
- [Disclaimer](#disclaimer)

---

## Features

- **Unauthenticated user creation:** Generates a user on the target system.
- **Token retrieval:** Acquires authentication tokens using the created user.
- **Remote command execution:** Executes arbitrary shell commands on the target system.

---

## Requirements

- Python 3.8+
- Modules:
  - `argparse`
  - `binascii`
  - `json`
  - `random`
  - `requests`
  - `time`
  - `urllib3`

Install missing modules using pip:

```bash
pip install requests
```
# Usage
Command-line Options

```
python exploit.py -u  [-t ]
```
# Example
```
python exploit.py -u https://192.168.1.100:8443 -t http://127.0.0.1:8080
```
Parameters
```
-u	(Required) Target URL of the F5 BIG-IP TMUI system.
-t	Proxy server (optional), e.g., http://127.0.0.1:8080.
```
# How It Works

    Generate Credentials: Randomly generates a username and password.
    User Creation: Attempts to create a new user on the target using a specially crafted request.
    Token Retrieval: Logs in with the new user to obtain a session token.
    Command Execution: Executes arbitrary commands via the token.

# Key Functions

    generatesth(num): Generates random alphanumeric strings of length num.
    unauth_create_user(target, username, password, proxy): Creates a user on the target system.
    get_token(target, user, passwd, proxy): Retrieves an authentication token for the created user.
    exec_command(target, token, cmd, proxy): Executes arbitrary commands on the target system.

# Disclaimer
```
This script is intended for educational and research purposes only. Unauthorized use of this script against systems you do not own or have explicit permission to test is illegal and unethical.
```
# !!!!Use responsibly!!!!!