Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

UNCLASSIFIED//LES
connectstothesamenetworkwithadifferentnetworkinterface(e.g.switchesfromwiredtowireless)
thenFulcrumwillstopworkingbu tthepivotmachinewillremainonline.
3.3 ARPSCANNINGAND/ORARPSPOOFINGMAYATTRACTATTENTIONFROM
SECURITYPRODUCTS
Description:TheuseofAR PscansandARPspoofsonanetworkmaydrawtheattentionofsecurity
productsdeployedonthepivotmachineoranywhereonthenetwork.
Reason:FulcrumusesgratuitousARPrepliesforitsMITMattackandwillsometimesuseARPrequestsin
ascanlikefashioninordertofindthetarget.Variousclassesofsecurityproductsincludingsome
IntrusionDetectionSystems(IDS)a ndPersonalFirewallsaswellaspurposebuilttools(e.g.arpwatch,
arpfreeze)candetectARPscansand/orARPspoofs.Sometoolsevengoastepfurtherandthwartthe
spoofingattempt.
RecommendedMitigatio n:Dont useFulcrumonnetworkswhic harelikelytohaveIDSand/ornetwork
monitoringinplace(e.g.corporateorenterprisenetworks).Wheneverpossible,identifywhichPerso nal
SecurityProducts(PSP)are runningonthepivotmachinetodetermineifthereareanyknownissues
withthatproduct.IfFulcrumisuntest edagainstthatspecificPSPorversion,thenaninhousetest
mimicking t he real environment should be done first in order to provide some measure of assurance.
AdditionalNotes:Thisisthesame techniquecurrentlyemployedonwirelessLANengagements.
3.4 FULCRUMWILLSTOPRUNNINGIFTHEPIVOTMACHINEIS REBOOTED
Description:IfthepivotboxwhichFulcrumisrunningonreboots,Fulcrumwillnotautorestart.
Reason:Fulcrumdoesnotprovideanypersistentmechanisms.
RecommendedMitigatio n:Whatevermechanismisusedtodeliver,command,andcontrolFulcrumis
responsibleforeitherrestartingFulcrumornotifyingtheoperatorthatthemachinehasbeenrebooted
andamanualrestartofFulcrum isrequired.
AdditionalNotes:
3.5 POTENTIAL LOSSOFCONTROLOFFULCRUM
Description:Fulcrummayrunindefinitelyifcommunicationsarelostwiththepivotmachine.
Reason:Fulcrumdoesnotimplementanycommunicationschannelorhaveasuicidedate.Fulcrumwill
runindefinitelyuntiliteitherhits the targetsuccessfully,unsuccessfullytries11times,thepivot
machineisrebooted,ortheparen tprocessdies(ifrunasaDLLviaLoadLibrary).Ifthetargetmachineis
rarelyorneveronlinewhenthepiv otmachineisandthecommunications channeltothepivotmachine
issevered,thenFulcrumwillrun indefinitelyuntiloneoftheseconditions occur.
UNCLASSIFIED//LES
Page5

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh