Rabid : Tool To Decode All Kind Of BigIP Cookies

Rabid is a CLI tool and library allowing to simply decode all kind of BigIP cookies.

Features

  • Support all 4 cookie formats
  • CLI tool & library
  • Hackable

Quick install

$ gem install rabid

Default usage: CLI

$ rabid ‘BIGipServer=1677787402.36895.0000’
Pool name:
Cookie type: IPv4 pool members
Raw cookie: BIGipServer=1677787402.36895.0000
Decoded cookie: 10.1.1.100:8080

Default usage: library

require ‘bigipcookie’
#IPv4 pool members, with pool name
bip = BigIPCookie::Decode.new(‘BIGipServer=1677787402.36895.0000’)
#Automatically decode
bip.auto_decode
#Print result
puts “Cookie: #{bip.decoded_cookie}”

Also Read – NekoBot : Auto Exploiter With 500+ Exploit 2000+ Shell

Installation

Production

Install from rubygems.org

$ gem install rabid

Gem: rabid

Install from BlackArch

From the repository:

#pacman -S rabid

From git:

#blackman -i rabid

PKGBUILD: rabid

Install from ArchLinux

Manually:

$ git clone https://aur.archlinux.org/rabid.git
$ cd rabid
$ makepkg -sic

With an AUR helper (Pacman wrappers), eg. pikaur:

$ pikaur -S rabid

AUR: rabid

Development

It’s better to use rbenv to have latests version of ruby and to avoid trashing your system ruby.

Install from rubygems.org

$ gem install –development rabid

Build from git

Just replace x.x.x with the gem version you see after gem build.

$ git clone https://github.com/Orange-Cyberdefense/rabid.git rabid
$ cd rabid
$ gem install bundler
$ bundler install
$ gem build bigipcookie.gemspec
$ gem install rabid-x.x.x.gem

Note: if an automatic install is needed you can get the version with $ gem build bigipcookie.gemspec | grep Version | cut -d’ ‘ -f4.
Run the library in irb without installing the gem

From local file:

$ irb -Ilib -rbigipcookie

From the installed gem:

$ rabid_console

Same for the CLI tool:

$ ruby -Ilib -rbigipcookie bin/rabid

Credit: Alexandre ZANNI (@noraj)

R K

Recent Posts

Bomber : Navigating Security Vulnerabilities In SBOMs

bomber is an application that scans SBOMs for security vulnerabilities. So you've asked a vendor…

14 hours ago

EmbedPayloadInPng : A Guide To Embedding And Extracting Encrypted Payloads In PNG Files

Embed a payload within a PNG file by splitting the payload across multiple IDAT sections.…

14 hours ago

Exploit Street – Navigating The New Terrain Of Windows LPEs

Exploit-Street, where we dive into the ever-evolving world of cybersecurity with a focus on Local…

3 days ago

ShadowDumper – Advanced Techniques For LSASS Memory Extraction

Shadow Dumper is a powerful tool used to dump LSASS (Local Security Authority Subsystem Service)…

4 days ago

Shadow-rs : Harnessing Rust’s Power For Kernel-Level Security Research

shadow-rs is a Windows kernel rootkit written in Rust, demonstrating advanced techniques for kernel manipulation…

2 weeks ago

ExecutePeFromPngViaLNK – Advanced Execution Of Embedded PE Files via PNG And LNK

Extract and execute a PE embedded within a PNG file using an LNK file. The…

3 weeks ago