Vault7: CIA Hacking Tools Revealed
Navigation: » Latest version
Owner: User #71467
Powerman-1r Testing
Powerman-1r Testing
Xetron delivered ROCEM version 1.1 for 3560G. Testing ROCEM for operational use on JQJADVERSE. Operator was not able to provide a configuration for the 3560G - we only know that this 3560G is a core switch with a router on a stick configuration and in a VTPVLAN Trunk Protocol enviroment. Conop will be to first use ROCM to survey device and then subsequently use ROCEM to throw HG. We are testing with a 3560G-24-PS, although Xetron's readme lists this ROCEM release is for 3560G-24-TS. It is not believed that the power over ethernet feature should affect the implant.
Testing Summary
- Readme needs to be changed - show switch detail does not exist in this IOSApple operating system for small devices version
- Smoke Test - Survey completed successfully
Progress/Notes
- Smoke Test - Survey 3560G with ROCEM
- 3560G is configured to use AAASecurity Server from Cisco server to authenticate users as well as authorize commands and log all commands entered
- Verified that AAASecurity Server from Cisco is logging show commands when entered in 3560G through regular telnet session
- Followed Xetron Powerman-1R readme procedure to use ROCEM to execute show commands
- ./rocem_c3560-ipbase-mz.122-35.SE5.py -i -f fill.bin 192.168.111.1
- Entered y to proceed
- 3560# prompt appeared - no creds were netered
- Executed show commands from readme successfully - show switch detail does not exist in this IOS
- Output of "who" command shows ROCEM vty session from ICON-CT IP and no username
- Typed exit at ROCEM prompt - session closed, no logs generated to AAASecurity Server from Cisco server. Output of "who" shows vty session for ROCEM is gone. No logs in 3560G logging buffer.