Spy Files 3
wikileaks.org
wikileaks.org
There are many interesting documents here, for example the "Finfisher FINFly ISP 2.0 Infrastructure Product Training" [1] which is a presentation/guide from www.gammagroup.com about how to use their software to "infect" the target and collect information about it.
[0] - https://news.ycombinator.com/item?id=6329435
[1] - https://wikileaks.org/spyfiles/docs/GAMMA_2010_FinfFINFISP_e...
btw reading some of those files and seeing the presentations remind me of the animated tv show Archer...
Yes, I am a very heavy critic of US spying and so on, over reaching, but equally, the info released must have some filtering so that stuff that is relevant to the general public is released and stuff that is really, genuinely, dangerous is held back. If an independent journalist/lawyer team say something should be held back, I think we have to, even if reluctantly, accept that. So, exactly like the Guardian people are behaving.
I want intelligent considered leaks, not dumps like this. And in some ways, this is not too dissimilar to the NSA slurping data. Mass dump, mass slurp. Neither are good.
It's just, the data itself are useless if you don't find some narrative, some story in it.
And, frankly, Assange himself admitted it before that just releasing dumps and hoping for people to find something in it is not the best thing to do.
1) ADMF-Client & Infection GUI
These seem to be HP Compaq computers, running Windows 7 Ultimate, FinFlyISP GUI and a XMPP client(which runs over TLS and is secure). This is a tool for LEA to use which interfaces with the ADMF backend for managing infections, selection of infection methods, realtime status info and management of all components.
2) ADMF - Central Administration Function
This is the backend which all the LEA terminals in 1 connect to. These are HP DL380 G6 Intel Xeon X5550 @ 2.67GHz servers running hardened Debian(by Dreamlab best practices). It is a core component of their infrastructure and communicates in realtime with all their other component systems. It stores the configuration and initiation of infections. Realtime exchange of info and states(target coming online, being infected, etc.) Contains RFC XMPP used for secure encrypted communications.
3) Network Data processing component (iProxy/NDP01/NDP02)
Infections are remotely activated by ADMF in 2 via the GUI. Each NDP is bridged with 10GB/s fiber bypass module. Incase of hardware/logical failures this module switches automatically to by-pass mode. Thus traffic will never be interrupted. ATTENTION this is highly dynamic bridge, do not change any configuration manually. NDP has been specially configured for his network, any changes are tightly coordinated with Dreamlab.
4) Radius Probe(RP01/RP02)
Realtime monitoring of AAA processes which include:
1. Targets coming online
2. Receiving IP Addresses
3. Changing IP Addresses
4. Going offline
Recording of RADIUS authentications and accounting dialogues. Being always up to date of target IP RP sends info to ADMF, the ADMF provisions the NDP. Running same hardware/OS as 3. The RPs have bidirectional connection with broadband remote access server(BRAS) [1] which are what connect to the global internet from a ISPs network. BRAS aggregrates user sessions from access network. This is where ISPs can inject policy management and QOS. Aggregrates DSLAM connections from locally dispersed in an ISP area network.
Communications Visualized
The slide explains that communication of all components always is initiated towards the ADMF.
http://i.imgur.com/qOQfVYd.png
Use Cases
1. GUI->ADMF [Infect a target]
2. ADMF->Radius prove [Start monitoring/set a trap on target]
3. Radius->ADMF->NDP/iProxy [Handover of IP]
4. iProxy->NDP [iProxy requests NDP to analyse datastream on IP and "interesting" traffic]
5. NDP->iProxy [Handover traffic matching request]
6. iProxy [changes traffic and modifies data by adding infection parts]
7. iProxy->NDP [iProxy sends modified traffic data to NDP]
8. NDP Reinject [NDP recalculates checksums/resequences TCP/IP packets and reinjects traffic into the stream]
9. Target infection done [Data successfully sent to target]
[1] http://en.wikipedia.org/wiki/Broadband_Remote_Access_Server
EDIT: What we need is a menu/list of the infections available to staff
http://en.wikipedia.org/wiki/FinFisher
It talks about the "infection" and its "use by repressive regimes" among other things.
So I interpret this as a system that needs to run in full co-operation with the ISP or the owner of the fiber cables. Since that is usually who is managing the RADIUS setup.
Though I don't know why that cloud would be labeled "OSS"
Doesn't it mean that ADMF of FinFly somehow interferes with browser auto-update in order to upload its trojan to the target computer? I know browser update file must be somehow cryptographically signed, but NSA may have access to private RSA key used for browser updates, which allows such types of attacks. Isn't it?
Thank you.
* .gov
I'm going to guess that the title was edited again, so we don't have the intended context. What was the original title?
https://wikileaks.org/spyfiles/docs/GAMMA_2010_FinfFINFISP_e...