Re: [FD] F5 BIG-IQ authed arbitrary user password change

2014-05-04 Thread Jeff Costlow
This issue has been fixed in all releases after BIG-IQ 4.1, including 4.2 and 4.3. Please see F5¹s technical solution at http://support.f5.com/kb/en-us/solutions/public/15000/200/sol15229.html BIG-IQ 4.1 was in limited release and customers had already been asked to upgrade. No versions of BIG-IP a

Re: [FD] F5 BIG-IQ authed arbitrary user password change

2014-05-02 Thread Brandon Perry
Nm on ExploitHub. Here is the module: https://gist.github.com/brandonprry/2e73acd63094fa2a4f63 On Thu, May 1, 2014 at 5:10 PM, Brandon Perry wrote: > Hi, > > Detailed at this blog post (with pics!) is a vulnerability within F5 > BIG-IQ 4.1.0.2013.0. > > > http://volatile-minds.blogspot.com/201

[FD] F5 BIG-IQ authed arbitrary user password change

2014-05-01 Thread Brandon Perry
Hi, Detailed at this blog post (with pics!) is a vulnerability within F5 BIG-IQ 4.1.0.2013.0. http://volatile-minds.blogspot.com/2014/05/f5-big-iq-v41020130-authenticated.html A module for this will be uploaded to ExploitHub this evening that will change the root users password and log in over S