Code from highly respected F5 enterprise web security appliances basically runs tar as root on input from HTTP at /mgmt/tm/util/bash URL π€ And it's 2021.
@kravietz what could possibly go wrong?
@thatguyoverthere
Just an extra admin console :)
https://github.com/h4x0r-dz/RCE-Exploit-in-BIG-IP/blob/main/f5_rce.py
@kravietz 77 lines to own a "security" appliance π€£
A *Respected* Enterprise Security Appliance!
Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance. Website: privacytools.io Matrix Chat: chat.privacytools.io Support us on OpenCollective, many contributions are tax deductible!