Hacker News new | past | comments | ask | show | jobs | submit login
Obtaining Remote Code Execution in F5-Bigip via AJP Request Smuggling (praetorian.com)
1 point by bouncyhat on Oct 26, 2023 | hide | past | favorite | 1 comment



We identified a new pre-auth remote code execution bug in F5-BIGIP's management panel. Today is disclosure day, so we can't share all the details yet (need to give folks time to patch), but we do go into details about how to identify AJP Request smuggling and demonstrate if an application is vulnerable. If you're not familiar with this technique, it's definitely worth a look!




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: