Vault7: CIA Hacking Tools Revealed
Navigation: » Directory
Owner: User #524297
User #524297
Pages | Date | User |
---|---|---|
Attachments:
Blog posts:
-
[User #524297]: EDG Suggestion: Provide User Feedback
I would like to provide a suggestion to all EDGEngineering Development Branch developers:
If your tool does not provide adequate unambiguous feedback for all user interactions, then you are doing your users a disservice.
It is a commonplace EDGEngineering Development Branch misconception to believe that all users deploying EDGEngineering Development Branch tools are safely behind keyboards and monitor screens at DD2. This is very much not the case.
EDG tools are also deployed in the Field, sometimes in potentially dangerous areas. These are areas where "getting caught" doesn't mean lost network access anymore: it means apprehension, detention, and interrogation.
Precious time on target can be wasted quickly by officers having to reissue commands, debug installations, or verifying execution of a shoddily developed tool.
Wasted time means increased risk of exposure of the officer, the operation, and the capabilities.
The great news is that wasted time on target can be prevented by providing the end user immediate unambiguous feedback about results of user actions. So don't be lazy with your output!
-
[User #524297]: Interesting NTFSNT filesystem (Windows) filename bug...
Found an interesting bug on NTFSNT filesystem (Windows) by pure chance. Wonder if it has other potential uses.
Trying to delete a collection of music files off of the FS-01 share, one file in particular has a filename so long that it can't seem to be deleted. The cool thing is that it doesn't show up in command-line directory lists, or Explorer windows, without enabling hidden files.
Talking with User #1179925, seems like this is similar to something exhibited by ADSAda Specification (file) files as well.
Seems to be very persistent. The Windows APIApplication Programming Interface isn't having much luck deleting it either, even when given an UNCUniversal Naming Convention path.
SOLUTION: Prepending
\\?\
to the full path increased the allowed filename length, and allowed a Windows APIApplication Programming Interface delete call to be successful. -
[User #524297]: Slides for 28 May 2015 NERDS Talks : How to Git Better & How to Code Review
Below files are the slides used by User #1179925 and User #524297 at the 28 May 2015 NERDS talk.
My slides are obviously lacking my witty repartee, boyish charm, and animated GIFs. But you can probably get the gist of it.
('attachments' missing)
-
[User #524297]: Slowly but surely...
Atlassian products are now all online!
Jira is the only one that isn't on production hardware yet, but that's because it will live on the HICKOCK DMZDemilitarized Zone (so it got a bit of the Red Tape Treatment).
Any questions, /join #atlassian-support on IRCInternet Relay Chat (or flag down @User #1179751 or me about it).
-
[User #524297]: Pulling in old LIBIDO source code...
Can't get the history though. Any chance the old UDB SVNSoftware Virtual Network repository is still alive and kicking?
-
[User #524297]: Testing Blog Post
oh my!