Forum Discussion
jksingh_44237
Nimbostratus
Jan 04, 2010The remote load balancer suffers from an information disclosure vulnerability at port 80 and 443
I am looking a solution for this issue.....
I have BIGIP (BIG-IP 9.3.1 Build 37.1)
Port http (tcp/80)
Synopsis :
The remote load balancer suffers from an information disclosure vulnerability.
Description :
The remote host appears to be a F5 BigIP load balancer which encodes within a cookie the IP address of the actual web server it is acting on behalf of. Additionally,information after 'BIGipServer' is configured by the user and may be the logical name of the device. These values may disclose sensitive information, such as internal IP addresses and names.Contact the vendor for a fix.
Plugin output :
The first column is the original cookie, the second the IP address and the third the TCP port:
BIGipServerwww_http_pool=2248217772.20480.0000 255.255.255.127
80BIGipServerwww_http_pool=2181108908.20480.0000 255.255.255.127
80BIGipServerwww_http_pool=2114000044.20480.0000 172.20.1.126
80BIGipServerwww_http_pool=2097222828.20480.0000 172.20.1.125
80BIGipServerwww_http_pool=2046891180.20480.0000 172.20.1.122
80BIGipServerwww_http_pool=2063668396.20480.0000 172.20.1.123
80BIGipServerwww_http_pool=2080445612.20480.0000 172.20.1.124
80BIGipServerwww_http_pool=2197886124.20480.0000 255.255.255.127 80
Port https (tcp/443)
Synopsis :
The remote load balancer suffers from an information disclosure vulnerability.
Description :
The remote host appears to be a F5 BigIP load balancer which encodes within a cookie the IP address of the actual web server it is acting on behalf of. Additionally,information after 'BIGipServer' is configured by the user and may be the logical name of the device. These values may disclose sensitive information, such as internal IP addresses and names.Contact the vendor for a fix.
Plugin output :
The first column is the original cookie, the second the IP address and the third the TCP port:
BIGipServerwww_http_pool=2248217772.20480.0000 255.255.255.127
80BIGipServerwww_http_pool=2181108908.20480.0000 255.255.255.127
80BIGipServerwww_http_pool=2114000044.20480.0000 172.20.1.126
80BIGipServerwww_http_pool=2097222828.20480.0000 172.20.1.125
80BIGipServerwww_http_pool=2046891180.20480.0000 172.20.1.122
80BIGipServerwww_http_pool=2063668396.20480.0000 172.20.1.123
80BIGipServerwww_http_pool=2080445612.20480.0000 172.20.1.124
80BIGipServerwww_http_pool=2197886124.20480.0000 255.255.255.127 80
- Hamish
Cirrocumulus
- L4L7_53191
Nimbostratus
Hamish: thanks for your perspective on this - very good post. - Hamish
Cirrocumulus
More thoughts... - Hamish
Cirrocumulus
I got an answer from F5... - hoolio
Cirrostratus
Hi Hamish, - Hamish
Cirrocumulus
I've sent the request in via our supplier. Just waiting for a response now. - Hamish
Cirrocumulus
No CR. The request for enhancement was denied. The wording was a little... unflattering... - L4L7_53191
Nimbostratus
CR or not, this is a super valuable thread that lays out a bunch of great information for us. Many thanks. - rhoads_77011
Nimbostratus
jksingh, - L4L7_53191
Nimbostratus
Encrypt the cookies.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects