Vault 7: Projects
This publication series is about specific projects related to the Vault 7 main publication.
SECRET//20340424
active on the target laptop.
14. Repeat steps 3 through 6 on the target laptop. ExpressLane is not detected by the
security application.
12
15. Uninstall the security application from the target
laptop.
Security application has been
uninstalled.
12
16. Watermark the USB drive using
createpartition.exe.
Drive is now water marked. 1
17. Insert the USB drive in the target machine, but
do not execute the cover application.
Collection begins and completes
successfully
1
1.2 (S) Test Set 2 – ExpressLane (Kill Switch)
7.2.1 (U) Test Procedure 2.1 – Windows XP Professional, SP2 Operating Systems
Testing
(S) The following test procedure tests the ability of ExpressLane to covertly corrupt the
license files of the biometric application which will force a visit to re-install the software.
(S) Setup steps:
1. Receive target Panasonic CF-19 Toughbook laptop equipped with various biometric
applications and Windows XP Professional, SP2 provided by the customer.
(S) Testing steps:
Step Action Expected Result Req
1.
Using MOBS_UPGRADE.exe on the cover
application USB drive, install the cover
application on the target computer. Restart the
target computer.
mobslangsvc.exe service is running
on the target computer after the
restart.
1, 2,
6
2. Use createpartition.exe, to allocate 50% of a
commercial USB drive to a hidden partition and
set the install time to 5 minutes.. Set the Kill
date to 1day earlier. (Yesterdays Date) Use
“View Partition” to verify that the kill data has
been set and that the USB drive now is 50%
smaller than what it originally was.
A hidden partition was created on the
commercial USB drive.
7, 8
3. Using a hex editor, view the USB drive and look
for the expiration date that you set with the
utility createPartition.exe.
Expiration date is not found in plain
text or numeric data.
1
4. On the target computer, open the license files
and copy the license line to a text file so that you
can preserve the original and reference it.
11
5. Insert the USB drive into the target computer.
After 30 seconds the light on the USB drive will
begin to show disk activity. Remove the USB
drive from the system at this point.
No pop up should occur. 2
6. Check the license files, they should have been
modified and will no longer match the original
license files.
Both license files were modified. 9,
10,
11
7. Cut and copy the original license files back into License files are restored back to their 10
SECRET//20340424
6
ExpressLane-3_1_1-TPP-FINAL.pdf