Vault7: CIA Hacking Tools Revealed
Navigation: » Latest version
Owner: User #71467
JQJHAIRPIECE - ROCEM TESTING
Testing Summary
Progress/Notes
User #13205547 - 7-9-15
Testing in support of JQJHAIRPIECE
"This release is for hairpiece-1r. hairpiece-1r is released as a part of ROCEM 1.1.
Target: hairpiece-1
Platform: 2960S IOSApple operating system for small devices Version:
c2960s-universalk9-mz.122-55.SE8"
Misc. Test Notes:
- SE7 and SE8 IOSApple operating system for small devices on the box, need SE8 for testing. Changed system boot, unable to load SE8. Deleted SE7 from the switch, reload, successfully loaded SE8.
- Test Infrastructure Information:
- Target Switch - 2960S-MgtSW / IP Address 192.168.21.2
- VMs
- ICON1-UbuntuDesktop12.04_x64-LTS 172.20.12.22 - Command and Control
- scd-proxy - scripting telnet session (JQJHAIRPIECE-log)
- Solar Winds Network Management - 10.9.8.22
- AAA Server 10.9.8.25
- Smoke Test - Survey with ROCEM
- 2960S is configured to log snmp traps and syslogs to Solarwinds (hairpiece-1r)
- 2960S is configured to use AAASecurity Server from Cisco server for telnet sessions
- Executed ROCEM per readme -
sudo ./rocem_c2960s-universalk9-mz.122-55.SE8.py -i -f fill.bin 192.168.21.2
- Output of "who" command before ROCEM shows my console session and my vty session on line 1:
2960S-MgtSW#who
Line User Host(s) Idle Location
0 con 0 root idle 00:03:11
* 1 vty 0 root idle 00:00:00 10.9.8.96
2 vty 1 idle 00:00:09 172.20.12.22- Followed Hairpiece-1r readme procedure to use ROCEM to execute show commands
- ./rocem_c2960s-universalk9-mz.122-55.SE8.py -i -f fill.bin 192.168.21.2
- Entered y to proceed
- 2960S-MgtSW# prompt appeared - no creds were entered
- Executed show commands from readme successfully. No log entries showed up from performing a "show log," no SNMPSimple Network Management Protocol entries seen on Solar Winds. No commands were logged to AAA.
- Entries were logged on AAASecurity Server from Cisco server at start and end of ROCEM session -
Jul 13 08:39:54 ubuntuserver tac_plus[1223]: connect from 172.31.255.2 [172.31.255.2]
Jul 13 08:39:58 ubuntuserver tac_plus[1234]: connect from 172.31.255.2 [172.31.255.2] - Output of "who" command shows ROCEM vty session from ICON-CT IP and no username
- Typed exit at ROCEM prompt - session closed, no logs generated, however SNMP trap for the connection close is logged: loctcpConnOutBytes.192.168.21.2.XX.XXX.XX.XX (???).22.54605 = 78 loctcpConnInBytes.192.168.21.2.XX.XXX.XX.XX (???).22.54605 = 847 loctcpConnElapsed.192.168.21.2.XX.XXX.XX.XX (???).22.54605 = 0.50 second tcpConnState.192.168.21.2.XX.XXX.XX.XX (???).22.54605 = synReceived(4) tslineSesType.2.1 = telnet(5) snmpTrapOID = CISCOTRAP-MIB:tcpConnectionClose sysUpTime = 23 hours 15 minutes 19.24 seconds