Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

UNCLASSIFIED//LES
UNCLASSIFIED//LES Page11
5 CONFIGURATION
5.1 FULCRUM
Therearethreewaystoprovidecon figurationdatatoFulcrum:
1. Commandlineparameters
2. ConfigurationFile(f.cfg)
3. CompiledParameters
Fulcrumsearchesforconfiguration datainthespecificorderabove,stoppingassoonasoneofthemis
located.Allrequiredconfig urationfieldsmustbepresentintheirentiretywithinthemethod used.If
theyarenot,thenFulcrumwillshutd own.Inotherwords,youcannotprovidesomeparameter svia
commandlineandothersviaconfigurationfileoranyothercombinationofmethods.Anyoptionalfield
thatisnotpresentinthemethodusedwillbeusedthebuiltin defaults.
5.1.1 COMMANDLINEPARAMETERS
Fulcrumfirstlooksforthepresence ofcommandlineparameterswhenrunasanEXEorvia
rundll32.exe.Ifthereareanyparame tersatall,thenFulcrumattemptstofulfillalloftherequired
configurationdatafromthecommandlineonly.Ifanyrequiredparameterismissing,theapplication
willexitwithanerrorcode.Nooptio nalparameterscanbesuppliedviathecommandlineandallof
themarefulfilledusingtheapplicationdefaults.Theorderinwhichtheparametersareprovidedmust
be exactly as shown.
Theusageofcommandlineparamete rsisthefollowing
[VictimMACAddress][HijackMACAddress][MillisecondsbetweenSpoofs][InjectedURL]
Forexample:
AA:AA:AA:AA:AA:AABB:BB:BB:BB:BB:BB1000http://test.com/cool.jpg
5.1.2 CONFIGURATIONFILE
NOTE:TheFulcrumconfigurationfileisencryptedwitha256bi tsymmetrickeyusingtheAESalgorithm.
Theencryptionanddecryptionoftheconfigurationfileisdoneusingthe
FULCRUMENCRYPTERutility.
Ifnocommandlineparametersarepresent, Fulcrumwilllookforafilenamef.cfgresidinginthesame
directorythattheFulcrumbinary(f32.exe)islocated.Ifthisfileisf ound,Fulcrumattemptstodecryptit
andacquirethenecessaryconfigurationdatafromit.Ifthereareproblemsaccessing,decry pting,or
parsingthisfileorifanyrequiredparameterismissing,thenFulcrumwillexitwithanerrorcode.

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh