Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
1
SECRET//NOFORN
(S)ARCHIMEDES1.2
(S//NF)Thisdocumentissupplementaltothefollowingdocuments:
FulcrumUserManual0.6
Archimedes1.0UserGuide
Archimedes1.1Addendum
(S//NF)Pleaseseetheabovedocumentsforacompletedescriptionofthetool’sfunctionality.Archimedes1.2isa
QRCupdatetothe1.1versionofthetoolthatincludessupportforrunningthetoolinasurveymodeandobeying
awhitelistoftargethosts.
(S//NF)Archimedes1.2makesthefollo wingmodificationstothe1.1version:
1. AddsSURVEY_ONLY(SO)optionasaninjectionmethod”.ThiscausesArchimedestologinformation
aboutthetarget’sHTTPrequeststoalocalfile.
2. AddsHOST_WHITELIST(HW)configurationoption.Ifthewhitelistisprovided,thenArchimedeswillonly
injectintohoststhatmat chnamesontheprovidedlist.
3. ChangesthecommandlineparameterformatforEXEsandDLLstou seargumentswitchesratherth ana
fixedorderofparameters.Notethatthismaybreakcompatibilitywithexi stin gscripts.
4. ChangesthedefaultvalueforINJECTION_METHOD(IM)toSURVEY_ONLY(SO),thedefaultvaluefor
VERIFY_ROUTE(VR)toFALSE,andthenumberofinjectionattemptsto5.
5. Replacesthereadablestringsusedintheconfigurationfile(andtospecifyinjectionmethods)withnon
alertingabbreviations.
(U)FILEINFORMATION
(S)AppendixBcontainsalistoftheb inariesdeliveredinArch imedes1.2alongwithMD5sumsandfilesizesthat
canbeusedtoverifyfileintegrity.
!!!DEBUGBINARI ESARECLASSIFIEDSECRET//NOFORNANDSHOULDNOT/NOTBEDEPLOYEDONTARGET!!!
(S//NF)Notethatthed eliveryincludesbothdebugandreleasebuildsofeachbinary.Thedebugbuildscontain
additionalinstru mentationthatcanbehelpfulinpinpointingerrorsandunexpectedbehaviorandwillgenerate
loginformationthatcanbeusedtotracetheprogram’sexecution.Debugversion sshouldnotbedeployed
outsideofac ontrolledCLASSIFIEDenvironment.Theadditionalinformationinthemmakesthesoftware
particularlyvulnerableto reverseengineeringandanalysis.Debugversionsofthetoolshouldbeusedin
controlledtestenvironmentsonly.

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh