Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
SECRET//NOFORN
(S//NF)Notethatthed eliveryincludesbothdebugandreleasebuildsofeachbinary.Thedebugbuildscontain
additionalinstru mentationthatcanbehelpfulinpinpointingerrorsandunexpectedbehaviorandwillgenerate
loginformationthatcanbeusedtotracetheprogram’sexecution.Debugversion sshouldnotbedeployedona
machinethatwedonothavephysicalcontrolovertheadditionalinformationinthemmakesthesoftware
particularlyvulnerableto reverseengineeringandanalysis.Debugversionsofthetoolshouldbeusedin
controlledtestenvironmentsonly.
(U) NEWOPTIONS
(S)ROUTEVERIFICATION CHECK
(S//NF)Priortoperforminganinjectiona ttack,theoriginaltoolperformsa“RoutingVerification”stepthatwould
oftenresultinah andlederrorthatcausedth eprogramtoterminate.Itisbelie vedthatthefailuremaybecaused
bynetworkcardincompatibilityortheLANinfrastructure.Anexampleoftheerrori sshownbelow.
(S//NF)Archimedesaddsth eoptiontodisablethischeckandcontinuewithnormaltooloperation.Testinghas
shownthatthiscanenableArchimedestosuccessfullyperformtheattackinenvironmentswherethetoo lwould
previouslyerrorand exit.
(S//NF)Thisnewoption isarequiredparameterinthecon figurationfileandisprovidedas:
VERIFY_ROUTE=TRUE
or
VERIFY_ROUTE=FALSE
(S//NF)ThevalueTRUEresultsintheoriginalroutingcheckbeingperformed.ThevalueFALSEdisablestherouting
check.
(S)INJECTIONMETHOD
(S//NF)TheINJECTION_METHODisspecifiedintheArchimedesconfigurationfile.Inadditiontothemethods
supportedbyFulcrum0.6.1,ArchimedesaddssupportfortheHIDDEN_IFRAMEoption.Thismethodwill
producethefollowingHTML:
<html>
<head>
<title></title>
<style type="text/css">
html, body
{
overflow: hidden;
margin: auto;

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh