Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

Pg. 07
Boot PersistenceBoot PersistenceBoot
Persistence
Does this command execute programs exclusively or shell commands as well? If cmd,
we may want a CMD command or just tell the users to use “cmd /C”.
EXEC – allow operator to determine cmd or not
Get:
Command needs dword offset/size to support 4.5.1.4/4.5.2.4.
No change
What does override flag do for the GET command?
Upload immediately – do this command first
Is dword 4GB enough for files?
No change
Is there any way to get a file listing except via cmd?
No
What happens if a directory is selected?
Return error
Put:
Command needs dword offset to support 4.5.1.4/4.5.2.4.
No change
Is dword 4GB enough for files?
No change
What happens if the file already exists (overwrite?)
Force overwrite
What happens if the file refers to a directory?
Return error
Memload:
Is nickname really what you want to transmit or is an internal memload ID enough and
the server views the user “nickname” on the backend?
YES – the operator understands this
Does this command only support nod persistent dlls or pic or axe as well?
Memunload:
DLL – only

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh