Vault 7: Projects

SECRET//20340105
(S) Testing steps
Step Action Expected Result Req
1.
Advance the clock more than 180 days from the
current system time and reboot.
DarkSeaSkies should be uninstalled. 3
7.4 (S) Test 4 – DarkSeaSkies Removal
(U) This test procedure tests requirement 4.
(S) Setup Steps:
1. Run the test script to ensure that the tool is installed and running.
2. Ensure that the target machine’s clock is past the start date that was placed in the
executable (i.e.…3/22/2009).
(S) Testing steps:
Step Action Expected Result Req
1.
On the target set the nvram status variable to a 1
and then reboot the machine.
The nvram variable for status is:
$(cat status.guid):$(cat status.name)
Upon reboot the tool will be
removed.
6
2.
On the target set the nvram status variable to a 5
and then reboot the machine.
After rebooting the machine the tool
will remove itself.
6
3.
Power up the machine and then before it is
finished booting hard power the system off. Do
this 6 times in a row with no successful boots.
After the sixth failed boot the tool
will remove itself.
6
4.
Cause a kernel panic by issuing the kwrite
command and writing a zero to one of the
following memory locations:
0x5057d4 – for OSX 10.5.2 through 10.5.4
0x5077d4 – for OSX 10.5.5
Repeat this step three times.
After the third kernel panic in a row
the tool will remove itself.
6
5.
Reduce the count limit to 2 by changing the
nvram variable.
$(cat warning_threshold.guid):$(catwarning_threshold.name)
Then reboot the machine and cause a kernel
panic.
After reboot the tool will remove
itself.
6
6.
Reduce the count limit to 1 by changing the
nvram variable
$(cat warning_threshold.guid):$(cat warning_threshold.name)
Then reboot the machine and hard power off the
machine while it is booting back up.
This will cause the tool to remove
itself.
6
8 (U) Test Report
8.1 (U) Requirements Verification Matrix
(U) The Requirements Verification Matrix in Table 8.1.1 displays six different letter keys
to signify how well the tool meets the user requirement. The meaning of each letter key is
shown below.
Identifier Meaning
SECRET//20340105
4