Ron Bowes · @iagox86
861 followers · 123 posts · Server infosec.exchange

I'm excited to share of my work that came out today! Specifically, a handful of vulnerabilities in devices that I worked on through the summer, and worked with the vendor to get patched (F5 was awesome to work with, btw!).

I wrote a super detailed #blog post, and also wrote a full PoC. modules (both for the exploits and some post-exploitation data-gathering) are incoming as well!

The most important of the issues is via a vulnerability in the interface (), which is pretty cool (though requires a confluence of conditions to actually matter). I also had to bypass to actually exploit this on the path I chose, which is kinda cool.

The other is authenticated RCE, to which they assigned , though even I, the person who found it, doesn't really think it's a big deal. It's a nice way to get a session on your test box, at least?

I also published a bunch of my #tools for analyzing F5, including scripts to build, parse, and requests to their proprietary (I think?) database protocol (these require a valid login to use, but there's no user separation so there's a bit of ).

I'll also be speaking about this research in much more detail (as much as I can in 45 minutes :) ) in my talk on Dec 2!

#f5 #BIGIP #blog #metasploit #rce #csrf #soap #cve_2022_41622 #selinux #cve_2022_41800 #meterpreter #tools #mitm #LPE #Hushcon

Last updated 2 years ago