CISA: Hackers abuse F5 BIG-IP cookies to map internal servers

Teilen:

CISA is warning that threat actors have been observed abusing unencrypted persistent F5 BIG-IP cookies to identify and target other internal devices on the targeted network.

By mapping out internal devices, threat actors can potentially identify vulnerable devices on the network as part of the planning stages in cyberattacks.

“CISA has observed cyber threat actors leveraging unencrypted persistent cookies managed by the F5 BIG-IP Local Traffic Manager (LTM) module to enumerate other non-internet facing devices on the network,” warns CISA.

“A malicious cyber actor could leverage the information gathered from unencrypted persistence cookies to infer or identify additional network resources and potentially exploit vulnerabilities found in other devices present on the network.”

F5 persistent sessions cookies

F5 BIG-IP is a suite of application delivery and traffic management tools for load-balancing web applications and for providing security.

One of its core modules is the Local Traffic Manager (LTM) module, which provides traffic management and load balancing to distribute network traffic across multiple servers. Using this feature, customers optimize their load-balanced server resources and high availability.

The Local Traffic Manager (LTM) module within the product uses persistence cookies that help maintain session consistency by directing traffic from clients (web browsers) to the same backend server each time, which is crucial for load balancing.

“Cookie persistence enforces persistence using HTTP cookies,” explains F5’s documentation.

“As with all persistence modes, HTTP cookies ensure that requests from the same client are directed to the same pool member after the BIG-IP system initially load-balances them. If the same pool member is not available, the system makes a new load balancing decision.”

These cookies are unencrypted by default, likely to maintain operational integrity with legacy configurations or due to performance considerations.

Starting in version 11.5.0 and onward, administrators were given a new “Required” option to enforce encryption on all cookies. Those who opted not to enable it were exposed to security risks.

However, these cookies contain encoded IP addresses, port numbers, and load-balancing setups of the internal load-balanced servers.

For years, cybersecurity researchers have shared how the unencrypted cookies can be abused to find previously hidden internal servers or possible unknown exposed servers that can be scanned for vulnerabilities and used to breach an internal network. A Chrome extension was also released for decoding these cookies to aid BIG-IP administrators troubleshoot connections.

According to CISA, threat actors are already tapping into this potential, exploiting lax configurations for network discovery.

CISA recommends that F5 BIG-IP administrators review the vendor’s instructions (also here) on how to encrypt these persistent cookies.

Note that a midpoint “Preferred” configuration option generates encrypted cookies but also allows the system to accept unencrypted cookies. This setting can be used during the migration phase to allow previously issued cookies to continue to work before enforcing encrypted cookies.

When set to “Required,” all persistent cookies are ciphered using strong AES-192 encryption.

CISA also notes that F5 has developed a diagnostic tool named ‘BIG-IP iHealth’ designed to detect misconfigurations on the product and warn admins about them.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:28 pm, Juni 22, 2025
Wetter-Symbol 25°C
L: 24° | H: 27°
wenige Wolken
Luftfeuchtigkeit: 50 %
Druck: 1014 mb
Wind: 15 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
24° | 27°°C 0 mm 0% 17 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 16 mph 77 % 1015 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 9 mph 86 % 1013 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 24°°C 1 mm 100% 15 mph 95 % 1018 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 25°°C 0 mm 0% 15 mph 50 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 17 mph 48 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 22°°C 0 mm 0% 13 mph 54 % 1012 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 10 mph 64 % 1012 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 13 mph 76 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0.2 mm 20% 13 mph 81 % 1011 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
15° | 15°°C 0.2 mm 20% 13 mph 60 % 1013 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 13 mph 46 % 1014 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,045.12
-1.22%
Ethereum(ETH)
€1,972.48
-6.95%
Fesseln(USDT)
€0.87
0.01%
XRP(XRP)
€1.77
-4.85%
Solana(SOL)
€115.81
-6.21%
USDC(USDC)
€0.87
-0.01%
Dogecoin(DOGE)
€0.135135
-4.88%
Shiba Inu(SHIB)
€0.000010
-4.77%
Pepe(PEPE)
€0.000008
-8.63%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen