[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fX4MadXVPr6peL7-xUbQWZkdhvq0ml7Y9wXs1UVmdZoQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1195,"How do I set up a remote debugging environment for an F5 BIG-IP vulnerability analysis?","To set up remote debugging for F5 BIG-IP, first locate the Java process (e.g., `restjavad`) using `ps aux |grep java` and find its PID. Modify the JVM options in `\u002Fetc\u002Fbigstart\u002Fscripts\u002Frestjavad` to add `-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8000`, then restart the `runit.service`. Finally, enable the firewall in the Web management panel under **System > Platform > Security** to allow incoming connections on port 8000, as documented in the [F5 BIG-IP Vulnerability Debugging Environment Setup](\u002Fnews\u002Ff5-big-ip-vulnerability-debugging-environment-setup).","\u003Cp>To set up remote debugging for F5 BIG-IP, first locate the Java process (e.g., `restjavad`) using `ps aux |grep java` and find its PID. Modify the JVM options in `\u002Fetc\u002Fbigstart\u002Fscripts\u002Frestjavad` to add `-agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8000`, then restart the `runit.service`. Finally, enable the firewall in the Web management panel under **System &gt; Platform &gt; Security** to allow incoming connections on port 8000, as documented in the [F5 BIG-IP Vulnerability Debugging Environment Setup](\u002Fnews\u002Ff5-big-ip-vulnerability-debugging-environment-setup).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Ff5-big-ip-vulnerability-debugging-environment-setup\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-do-i-set-up-a-remote-debugging-environment-for-an-f5-big-ip-vulnerability-an-1777480073959","F5 BIG-IP, vulnerability debugging, JVM debug, remote debugging, firewall",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},290,"F5 BIG-IP Vulnerability Debugging Environment Setup","f5-big-ip-vulnerability-debugging-environment-setup","Step-by-step guide to install and configure F5 BIG-IP for vulnerability debugging, including setup, tmsh usage, and log management.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article documents the details of building an F5 BIG-IP vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>F5 BIG-IP Installation\u003C\u002Fli>\u003Cli>F5 BIG-IP Vulnerability Debugging Environment Configuration\u003C\u002Fli>\u003Cli>Common Knowledge\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 F5 BIG-IP Installation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Download the OVA file\u003C\u002Fh3>\u003Cp>Download page: https:\u002F\u002Fdownloads.f5.com\u002Fesd\u002Fproductlines.jsp\u003C\u002Fp>\u003Cp>Before downloading, you need to register a user and apply for an activation code. Application address: http:\u002F\u002Fwww.f5.com\u002Ftrial\u003C\u002Fp>\u003Ch3>2. Installation\u003C\u002Fh3>\u003Cp>(1) Import OVA file in VMware Workstation\u003C\u002Fp>\u003Cp>(2) Set username and password\u003C\u002Fp>\u003Cp>After importing the virtual machine, enter the default username (root) and default password (default), then reset the passwords for the root user and admin user\u003C\u002Fp>\u003Cp>(3) Configuration\u003C\u002Fp>\u003Cp>Obtain IP via ifconfig, access https:\u002F\u002F\u003Cip>, log in using admin credentials\u003C\u002Fip>\u003C\u002Fp>\u003Cp>Enter activation code on the configuration page\u003C\u002Fp>\u003Cp>Enable SSH on the configuration page to allow SSH login\u003C\u002Fp>\u003Ch2>0x03 F5 BIG-IP Vulnerability Debugging Environment Configuration\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Configuration file location reference: 'CVE-2022-1388 F5 BIG-IP iControl REST Process Analysis and Authentication Bypass Vulnerability Reproduction'\u003C\u002Fp>\u003Ch3>1. Locate Java process\u003C\u002Fh3>\u003Cp>Check processes:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ps aux |grep java\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016716783_0_15a1992e99.png\">\u003C\u002Fp>\u003Cp>Locate process pid 6324, jar path \u002Fusr\u002Fshare\u002Fjava\u002Frest\u003C\u002Fp>\u003Cp>View process information for pid 6324:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd \u002Fproc\u002F6324\u002Fcwd\u003Cbr>ll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016725618_1_8e88a58357.png\">\u003C\u002Fp>\u003Cp>Locate file \u002Fetc\u002Fbigstart\u002Fscripts\u002Frestjavad\u003C\u002Fp>\u003Cp>Modify JVM_OPTIONS, add debug parameter -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8000\u003C\u002Fp>\u003Ch3>2. Locate service\u003C\u002Fh3>\u003Cp>Check status of all services:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>systemctl status\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Find service name corresponding to pid 6324: runit.service\u003C\u002Fp>\u003Cp>After adding debug parameter, restart service:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>service runit.service restart\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check if parameters have been modified:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ps aux |grep 8000\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016730797_2_bf127ddb5e.png\">\u003C\u002Fp>\u003Ch3>3. Enable firewall\u003C\u002Fh3>\u003Cp>In the Web management panel, navigate to System -&gt; Platform -&gt; Security\u003C\u002Fp>\u003Cp>Add rules as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016736759_3_4d32c1fd25.png\">\u003C\u002Fp>\u003Cp>Remote debugging successful, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016740093_4_77d9c5e636.png\">\u003C\u002Fp>\u003Cp>Use tmsh to view firewall rules, refer to\u003C\u002Fp>\u003Cp>https:\u002F\u002Fclouddocs.f5.com\u002Fcli\u002Ftmsh-reference\u002Fv15\u002Fmodules\u002Fsecurity\u002Fsecurity_firewall_management-ip-rules.html\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh -c 'list \u002Fsecurity firewall management-ip-rules'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016744200_5_67f468e548.png\">\u003C\u002Fp>\u003Ch3>4. Common JAR Package Locations\u003C\u002Fh3>\u003Cul>\u003Cli>\u002Fusr\u002Flocal\u002Fwww\u002Ftmui\u002FWEB-INF\u002Flib\u002F\u003C\u002Fli>\u003Cli>\u002Fusr\u002Fshare\u002Fjava\u002Frest\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Common Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. tmsh Usage\u003C\u002Fh3>\u003Cp>Reference Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fclouddocs.f5.com\u002Fapi\u002Ftmsh\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fclouddocs.f5.com\u002Fcli\u002Ftmsh-reference\u002Flatest\u002F\u003C\u002Fp>\u003Ch4>(1) Check Version\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh show \u002Fsys version\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) View All Configurations\u003C\u002Fh4>\u003Cp>Step-by-step Operations:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh\u003Cbr>list all-properties\u003Cbr>y\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>One-click operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo y | tmsh -c 'list all-properties'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) View user information\u003C\u002Fp>\u003Cp>Step-by-step operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh\u003Cbr>list auth\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>One-click operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh -c 'list auth'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Create administrator user (web and SSH login)\u003C\u002Fh4>\u003Cp>Reference: https:\u002F\u002Fclouddocs.f5.com\u002Fcli\u002Ftmsh-reference\u002Fv15\u002Fmodules\u002Fauth\u002Fauth_user.html\u003C\u002Fp>\u003Cp>Step-by-step operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh\u003Cbr>create auth user user123 password aaaaaaa1234 description \"Admin User\" shell bash partition-access add { all-partitions { role admin } }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Note that passwords must not contain special characters.\u003C\u002Fp>\u003Cp>One-click operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh -c 'create auth user user123 password aaaaaaa1234 description \"Admin User\" shell bash partition-access add { all-partitions { role admin } }'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) Delete user\u003C\u002Fh4>\u003Cp>Step-by-step operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh\u003Cbr>delete auth user test1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>One-click operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh -c 'delete auth user test1'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Execute commands using REST API\u003C\u002Fh3>\u003Cp>Administrator username and password required\u003C\u002Fp>\u003Cp>Access https:\u002F\u002F\u003Curl>\u002Fmgmt\u002Ftm\u002Futil\u002Fbash\u003C\u002Furl>\u003C\u002Fp>\u003Cp>Can execute bash commands and obtain return results\u003C\u002Fp>\u003Cp>Code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>3. Log-related\u003C\u002Fh3>\u003Ch4>(1) Search logs with specified keywords\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>grep -iR aaaaaaaa \u002Fvar\u002Flog\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Correspondence between web management backend and log files\u003C\u002Fh4>\u003Cp>Audit logs, located at System -&gt; Logs -&gt; audit, corresponding file \u002Fvar\u002Flog\u002Faudit\u003C\u002Fp>\u003Cp>User login history, located at Logins -&gt; History, corresponding file \u002Fvar\u002Flog\u002Fsecure\u003C\u002Fp>\u003Ch4>(3) Other log locations\u003C\u002Fh4>\u003Cul>\u003Cli>\u002Fvar\u002Flog\u002Frestjavad-audit.0.log\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fauditd\u002Faudit.log\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fbtmp\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Flastlog\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(4) View web access logs\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>journalctl \u002Fusr\u002Fbin\u002Flogger\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Clear all:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rm -rf \u002Fvar\u002Flog\u002Fjournal\u002F*\u003Cbr>systemctl restart systemd-journald\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the F5 BIG-IP vulnerability debugging environment, we can proceed to study the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article documents the details of building an F5 BIG-IP vulnerability debugging environment from scratch.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>F5 BIG-IP Installation\u003C\u002Fli>\u003Cli>F5 BIG-IP Vulnerability Debugging Environment Configuration\u003C\u002Fli>\u003Cli>Common Knowledge\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 F5 BIG-IP Installation\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Download the OVA file\u003C\u002Fh3>\u003Cp>Download page: https:\u002F\u002Fdownloads.f5.com\u002Fesd\u002Fproductlines.jsp\u003C\u002Fp>\u003Cp>Before downloading, you need to register a user and apply for an activation code. Application address: http:\u002F\u002Fwww.f5.com\u002Ftrial\u003C\u002Fp>\u003Ch3>2. Installation\u003C\u002Fh3>\u003Cp>(1) Import OVA file in VMware Workstation\u003C\u002Fp>\u003Cp>(2) Set username and password\u003C\u002Fp>\u003Cp>After importing the virtual machine, enter the default username (root) and default password (default), then reset the passwords for the root user and admin user\u003C\u002Fp>\u003Cp>(3) Configuration\u003C\u002Fp>\u003Cp>Obtain IP via ifconfig, access https:\u002F\u002F\u003Cip>, log in using admin credentials\u003C\u002Fip>\u003C\u002Fp>\u003Cp>Enter activation code on the configuration page\u003C\u002Fp>\u003Cp>Enable SSH on the configuration page to allow SSH login\u003C\u002Fp>\u003Ch2>0x03 F5 BIG-IP Vulnerability Debugging Environment Configuration\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Configuration file location reference: 'CVE-2022-1388 F5 BIG-IP iControl REST Process Analysis and Authentication Bypass Vulnerability Reproduction'\u003C\u002Fp>\u003Ch3>1. Locate Java process\u003C\u002Fh3>\u003Cp>Check processes:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ps aux |grep java\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016716783_0_15a1992e99-1.png\">\u003C\u002Fp>\u003Cp>Locate process pid 6324, jar path \u002Fusr\u002Fshare\u002Fjava\u002Frest\u003C\u002Fp>\u003Cp>View process information for pid 6324:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd \u002Fproc\u002F6324\u002Fcwd\u003Cbr>ll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016725618_1_8e88a58357-1.png\">\u003C\u002Fp>\u003Cp>Locate file \u002Fetc\u002Fbigstart\u002Fscripts\u002Frestjavad\u003C\u002Fp>\u003Cp>Modify JVM_OPTIONS, add debug parameter -agentlib:jdwp=transport=dt_socket,server=y,suspend=n,address=8000\u003C\u002Fp>\u003Ch3>2. Locate service\u003C\u002Fh3>\u003Cp>Check status of all services:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>systemctl status\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Find service name corresponding to pid 6324: runit.service\u003C\u002Fp>\u003Cp>After adding debug parameter, restart service:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>service runit.service restart\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check if parameters have been modified:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ps aux |grep 8000\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016730797_2_bf127ddb5e-1.png\">\u003C\u002Fp>\u003Ch3>3. Enable firewall\u003C\u002Fh3>\u003Cp>In the Web management panel, navigate to System -&gt; Platform -&gt; Security\u003C\u002Fp>\u003Cp>Add rules as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016736759_3_4d32c1fd25-1.png\">\u003C\u002Fp>\u003Cp>Remote debugging successful, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016740093_4_77d9c5e636-1.png\">\u003C\u002Fp>\u003Cp>Use tmsh to view firewall rules, refer to\u003C\u002Fp>\u003Cp>https:\u002F\u002Fclouddocs.f5.com\u002Fcli\u002Ftmsh-reference\u002Fv15\u002Fmodules\u002Fsecurity\u002Fsecurity_firewall_management-ip-rules.html\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh -c 'list \u002Fsecurity firewall management-ip-rules'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016744200_5_67f468e548-1.png\">\u003C\u002Fp>\u003Ch3>4. Common JAR Package Locations\u003C\u002Fh3>\u003Cul>\u003Cli>\u002Fusr\u002Flocal\u002Fwww\u002Ftmui\u002FWEB-INF\u002Flib\u002F\u003C\u002Fli>\u003Cli>\u002Fusr\u002Fshare\u002Fjava\u002Frest\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Common Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. tmsh Usage\u003C\u002Fh3>\u003Cp>Reference Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fclouddocs.f5.com\u002Fapi\u002Ftmsh\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fclouddocs.f5.com\u002Fcli\u002Ftmsh-reference\u002Flatest\u002F\u003C\u002Fp>\u003Ch4>(1) Check Version\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh show \u002Fsys version\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) View All Configurations\u003C\u002Fh4>\u003Cp>Step-by-step Operations:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh\u003Cbr>list all-properties\u003Cbr>y\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>One-click operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo y | tmsh -c 'list all-properties'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(3) View user information\u003C\u002Fp>\u003Cp>Step-by-step operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh\u003Cbr>list auth\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>One-click operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh -c 'list auth'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Create administrator user (web and SSH login)\u003C\u002Fh4>\u003Cp>Reference: https:\u002F\u002Fclouddocs.f5.com\u002Fcli\u002Ftmsh-reference\u002Fv15\u002Fmodules\u002Fauth\u002Fauth_user.html\u003C\u002Fp>\u003Cp>Step-by-step operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh\u003Cbr>create auth user user123 password aaaaaaa1234 description \"Admin User\" shell bash partition-access add { all-partitions { role admin } }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Note that passwords must not contain special characters.\u003C\u002Fp>\u003Cp>One-click operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh -c 'create auth user user123 password aaaaaaa1234 description \"Admin User\" shell bash partition-access add { all-partitions { role admin } }'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) Delete user\u003C\u002Fh4>\u003Cp>Step-by-step operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh\u003Cbr>delete auth user test1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>One-click operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tmsh -c 'delete auth user test1'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Execute commands using REST API\u003C\u002Fh3>\u003Cp>Administrator username and password required\u003C\u002Fp>\u003Cp>Access https:\u002F\u002F\u003Curl>\u002Fmgmt\u002Ftm\u002Futil\u002Fbash\u003C\u002Furl>\u003C\u002Fp>\u003Cp>Can execute bash commands and obtain return results\u003C\u002Fp>\u003Cp>Code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>3. Log-related\u003C\u002Fh3>\u003Ch4>(1) Search logs with specified keywords\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>grep -iR aaaaaaaa \u002Fvar\u002Flog\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Correspondence between web management backend and log files\u003C\u002Fh4>\u003Cp>Audit logs, located at System -&gt; Logs -&gt; audit, corresponding file \u002Fvar\u002Flog\u002Faudit\u003C\u002Fp>\u003Cp>User login history, located at Logins -&gt; History, corresponding file \u002Fvar\u002Flog\u002Fsecure\u003C\u002Fp>\u003Ch4>(3) Other log locations\u003C\u002Fh4>\u003Cul>\u003Cli>\u002Fvar\u002Flog\u002Frestjavad-audit.0.log\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fauditd\u002Faudit.log\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fbtmp\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Fwtmp\u003C\u002Fli>\u003Cli>\u002Fvar\u002Flog\u002Flastlog\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(4) View web access logs\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>journalctl \u002Fusr\u002Fbin\u002Flogger\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Clear all:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rm -rf \u002Fvar\u002Flog\u002Fjournal\u002F*\u003Cbr>systemctl restart systemd-journald\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>After setting up the F5 BIG-IP vulnerability debugging environment, we can proceed to study the vulnerability.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",23,"Onedaysec",3,"published","2026-02-02T07:25:19.684Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"F5 BIG-IP Vulnerability Debugging Setup Guide","F5 BIG-IP, vulnerability debugging, environment setup, installation, configuration, tmsh commands, REST API, log files",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],1198,1197,1196,{"title":39,"description":39,"image":39},"2026-07-24T15:37:08.947Z","2026-07-23T16:02:39.774Z","draft","2026-07-23T16:17:19.956Z"]