Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

UNCLASSIFIED//LES
UNCLASSIFIED//LES Page12
PARAMETER_NAME=<ParameterValue>
Hereisanexampleconfigurationfileinitsunencryptedform.
VICTIM_MAC=AA:AA:AA:AA:AA:AA
HIJACKED_MAC=BB:BB:BB:BB:BB:BB
MILLISECONDS_BETWEEN_SPOOFS=1000
INJECTED_URL=http://www.cnn.com
INJECTION_METHOD=DOUBLE_FRAME
USABLE_MEDIA_TYPES=text/html,*/*
USER_AGENT_WHITELIST=
USER_AGENT_BLACKLIST=
5.1.3 COMPILEDPARAMETERS
Ifnocommandlineparametersandnoconfigurationfilearepresent,Fulcrumwillusethedatathatwas
compiledintotheapplicationforitsrequiredparameters.Thisprovidesanothermethodofexecuting
FulcrumandavoidstheconfigurationfileondiskorthecommandlineparametersappearingintheTask
Manager.Thiswasoriginallyaddedtosupportinmemoryonlydeploymentandexecution.While
Fulcrumitselfcanbedeployedandexecutedinaninmemoryonlyfashion,theWPCAPProsupportDLL
willwritetemporaryfilestothediskandmakechangestotheregistry.Itisimportanttonotehowever,
thatthisinformationisstoredinplaintextinanunobfuscatedmannerinthebinary.
Inordertochangethesevalues,itisnecessarytogetadevelopertorecompiletheapplication.The
operationalneedforthecontinuedsupportofthisfeaturewillbereviewed.Thenitmayeitherbe
removedfromfutureversionsoralteredtoallowforeasiereditingbytheenduserswithoutrequiringa
developertobeinvolved.
5.1.4 CONFIGURATIONOPTIONS
ParameterName
Description
AcceptableValues
DefaultValue
VICTIM_MAC
TheMACaddressofthe
TargetMachineinthe
formof
XX:XX:XX:XX:XX:XX
00:00:00:00:00:01
FF:FF:FF:FF:FF:FE
inclusive
66:77:88:99:AA:BB
HIJACKED_MAC TheMACaddressofthe
HijackedMachine
(typicallytheDefault
gateway)intheformof
XX:XX:XX:XX:XX:XX
Thisparameterisalso
usedtoverifythatthe
applicationisrunningon
thecorrectnetwork.
00:00:00:00:00:01
FF:FF:FF:FF:FF:FE
inclusive
BB:CC:DD:EE:FF:00
MILLISECONDS_BETWEEN_SPOOFS
Thenumberof
02,147,483,647
1000

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh