F5 Big IP opens up vulnerability during configuration
F5 Networks’ popular load balancing software BIG-IP harbours a vulnerability that could let malicious code seep in using just an online form.
"Load balancing is an important web management process that keeps many internet services ticking," said F-Secure, which spotted the vulnerability. "Without it, banks, governments, and other organisations providing online services to large numbers of people would struggle to keep their websites running."
Senior security consultant Christoffer Jerkeby discovered the vulnerability during a routine assessment. More than 300,000 organisations including state bodies and large banks use BIG-IP, broadening the scope of potential damages.
"Further research found that, following a successful exploit, an adversary could turn the compromised device back against the organisation or even individuals using the affected services," it added.
F-Secure said it is yet to receive reports of misuse of this vulnerability.
"F5 is a popular technology and we found over 300,000 (potentially vulnerable) devices on-line. Google and services like Shodan can be used to search for these also. The F5 website also contains information on their clients and sectors," Dave Hartley, technical director at F-Secure, told SC Media UK.
He refrained from revealing the names of the vulnerable F5 clients, saying: "These companies may be at risk of compromise."
Curiously, BIG-IP itself is immune to the vulnerability. It creeps up only when an organisation mis-configures BIG-IP’s iRules, the procedures written in tool command language (Tcl) to direct incoming web traffic toward the correct web server.
"These iRules are created using the tool command language (Tcl). Certain coding practices that may seem perfectly functional and practical to an organisation can allow an attacker to inject arbitrary Tcl commands, which could be executed in the security context of the target Tcl script," the report said.
In some implementations of BIG-IP, injecting a malicious code can be as easy as filling an online form, F-Secure revealed.
The threat posed is way bigger than a simple data breach, Hartley told SC Media UK. "An attacker can leverage the issue to achieve much more than a data breach alone. If the prerequisites are met, it could result in an adversary taking full control of the F5."
However, the scope and depth of the attack will vary, depending on the objective of the attacker and the scale of operations of the target organisation, he said.
"The F5 is often used for perimeter security and traffic management and there have been issues identified in similar technologies in the past that have had a severe impact for some -- firewalls, anti-virus, e-mail sandbox technologies etc.," he explained.
Addressing the issue, F5 released a public advisory.
"This is not a vulnerability in Tcl, or F5 products, but rather an issue relating to coding practices used when writing Tcl code. As with most programming or scripting languages, it is possible to write code in a way that may create vulnerabilities. This is not something F5 can prevent the user from doing, as the issue does not lend itself to neither deterministic nor heuristic detection that covers all possible cases," it said.
"The Tcl documentation previously cited provides more comprehensive recommendations. However, the simple answer is that expressions in Tcl should always be braced," it added.
source scmagazineuk
Industry: Cyber Security
Latest Jobs
-
- Cyber Security Senior Consultant | London | FS
- London
- Apply today
-
London | FS | Cyber Security Senior Consultant We are looking for experienced cyber security consultant with experience helping clients within the financial services industry. The role will include, but not be limited to; Conduct cyber security assessments, develop strategies, and provide advice to clients. Oversee and deliver security improvements projects. Help clients understand and comply with financial sector regulations. Provide insights and thought leadership on emerging trends in cyber security. Current experience within a client facing, cyber consulting role within Financial Services is essential. All the usual badges are nice to have, although not essential- for example; ISO27001, CISSP, CISM etc etc Sponsorship is not available for this role. Applicants must be UK based and able to travel on occasion to client site and the office in London To find out more reach out to me on 07884666351 or chris.holt@dclsearch.com
-
- Senior Penetration Tester - UK - Ability to achieve security clearance.
- United Kingdom
- To attract the right person
-
Senior Penetration tester, who has the ability to achieve security clearance. (Visa sponsorships NOT available - sorry) UK based - remote first - occasional travel. Red teaming experience desirable. The successful person needs to have a history of engaging directly with customers (consultancy experience) technical delivery of penetration tests AND report writing. Limited travel - company operates a remote first approach. Must be living in the UK. Not one of the usual names in the pen testing industry. Looking for someone highly technical but looking to grow and develop their skills. Apply here or Reach out to me on chris.holt@dclsearch.com or 07884666351 All details kept discreet
-
- Cloud Architect- German Speaker
- Hungary
- Upto €48000 per year + bonus + benefits
-
As a Senior Pre-Sales Solutions Architect, you will play a pivotal role in driving our sales success by translating complex technical solutions into compelling proposals that resonate with our clients. You will collaborate closely with our sales teams to understand customer needs, design tailored solutions, and negotiate successful deals. Responsibilities: Solution Design: Develop comprehensive technical solutions that align with customer business objectives and industry best practices. Proposal Development: Create compelling proposals, including requirements gathering questionnaires, presentation materials, and Statements of Work (SOWs). Customer Engagement: Build strong relationships with clients, understanding their technical, business, and commercial requirements. Collaboration: Work closely with sales teams, delivery teams, and third-party partners to ensure successful project execution. Pricing Strategy: Define and deliver pricing strategies that align with customer needs and company objectives. Requirements: Experience in technical pre-sales or sales support roles. Proven track record in designing and delivering successful customer solutions. Strong technical foundation in areas such as VMware, Azure, AWS, cloud computing, and data center technologies. Excellent understanding of sales principles, account management, and negotiation techniques. Ability to explain complex technical concepts clearly and concisely. Experience working in international teams and supporting clients across multiple regions. Fluency in German and English is essential. Benefits: Competitive salary and benefits package Opportunity to work on challenging and rewarding projects Collaborative and supportive work environment Potential for career growth and advancement Please note that this role is focused on supporting German clients, but will also involve global client support as needed.