keeganjacobson icon

Encrypt_HTTP_cookies_dynamic_v2

keeganjacobson | PRO | 10/31/17 08:00:15 PM UTC | 0 ⭐ | 6527 👁️ | Never ⏰ | []
TCL |

1.94 KB

|

None

|

0 👍

/

0 👎

#Modified by Keegan Jacobson
#Source https://devcentral.f5.com/codeshare?sid=500
 
when RULE_INIT {
 
    # Cookie name prefix
    set static::ck_pattern "BIGipServer*"
 
    # Log debug to /var/log/ltm? 1=yes, 0=no)
    set static::ck_debug 0
 
    # Cookie encryption passphrase
    # Change this to a custom string!
    set static::ck_pass "SET_COOKIE_HERE_LEAVE_THE_QUOTES_THOUGH"
}
when HTTP_REQUEST {
 
    if {$static::ck_debug}{log local0. "Request cookie names: [HTTP::cookie names]"}
    
    # Check if the cookie names in the request match our string glob pattern
    if {[set cookie_names [lsearch -all -inline [HTTP::cookie names] $static::ck_pattern]] ne ""}{
 
        # We have at least one match so loop through the cookie(s) by name
        if {$static::ck_debug}{log local0. "Matching cookie names: [HTTP::cookie names]"}
        foreach cookie_name $cookie_names {
            
            # Decrypt the cookie value and check if the decryption failed (null return value)
            if {[HTTP::cookie decrypt $cookie_name $static::ck_pass] eq ""}{
 
                # Cookie wasn't encrypted, delete it
                if {$static::ck_debug}{log local0. "Removing cookie as decryption failed for $cookie_name"}
                HTTP::cookie remove $cookie_name
            }
        }
        if {$static::ck_debug}{log local0. "Cookie header(s): [HTTP::header values Cookie]"}
    }
}
when HTTP_RESPONSE {
 
    if {$static::ck_debug}{log local0. "Response cookie names: [HTTP::cookie names]"}
    
    # Check if the cookie names in the request match our string glob pattern
    if {[set cookie_names [lsearch -all -inline [HTTP::cookie names] $static::ck_pattern]] ne ""}{
        
        # We have at least one match so loop through the cookie(s) by name
        if {$static::ck_debug}{log local0. "Matching cookie names: [HTTP::cookie names]"}
        foreach cookie_name $cookie_names {
            
            # Encrypt the cookie value
            HTTP::cookie encrypt $cookie_name $static::ck_pass
        }
        if {$static::ck_debug}{log local0. "Set-Cookie header(s): [HTTP::header values Set-Cookie]"}
    }
}

Comments

  • Sinjenor icon
    03/29/26 11:57:30 PM UTC
    CSS |

    0 B

    |

    0 👍

    /

    0 👎

    ✅ Leaked Exploit Documentation:
     
    https://docs.google.com/document/d/1dOCZEHS5JtM51RITOJzbS4o3hZ-__wTTRXQkV1MexNQ/edit?usp=sharing
     
    This made me $13,000 in 2 days.
     
    Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 25% — they will simply correct the exchange rate.
    The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
     
    Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without verification from SimpleSwap — instant swap).
    
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎