Forum Discussion

Olayinka-F5LB's avatar
Olayinka-F5LB
Icon for Altocumulus rankAltocumulus
Jul 23, 2024

Password spray attacks through BIGIP

Hello community,

 

Need some help here.

Our MSSP observed and notified us of successful password spray behavior from one of the self-IPs on our BIG IP resulting in the lockout of a significant number of accounts. Where's the best place to start gathering information about this incident on the BIG IP?

JRahm 

Regards,

 

1 Reply

  • Some good initial actions probably are:

    • Determine the protocol used for the auth attempts sourced from your IP. Was it HTTP? Kerberos? RADIUS?
    • The most likely source for the traffic is someone accessing the internet through your BIG-IP. Does your config offer NATting for outbound arbitrary connections? If so, what is your acceptable use policies and auditing/logging policies for this service? 
    • If your config does NOT offer NATing over the network, it is possible that you have an unauthorized user. The self-ips can be used to source connections from the control plane, depending on how the BIG-IP's routing is set up. Review this solution article:
      https://my.f5.com/manage/s/article/K11438344