Cherry Blossom Mobile VPN Software Installation and User Manual
Cherry Blossom Mobile VPN Software Installation and User Manual
SECRET
SECRET
1.(U) Introduction
(S) Cherry Blossom includes a Mobile VPN capability, wherein the Mobile VPN
software can be installed on a server with a publicly-accessible IP address. This
server is typically an ICON workstation. [The SRI-developed Mobile VPN software
was developed to run on a workstation booted in Fedora Core 10; COG has
requested that it be modified to run on a workstation booted into Ubuntu 10.04.]
This document explains how the SRI/Fedora version of the Mobile VPN server
software is installed and operated.
(S) Knowing the IP address of the Mobile VPN server, by interacting with the
CherryTree database via a different ICON workstation, a Cherry Blossom operator
can task a Flytrap to open a VPN link between the Flytrap and the Mobile VPN
server. Through this link, the operator can then access client workstations on the
(private) LAN or WLAN side of the Flytrap and perform exploits against the client
devices. Additionally, the mission tasked to the Flytrap can instruct the Flytrap to
use the Mobile VPN server to proxy all network traffic.
a) Follow standard ICON procedures to boot to the “Fedora Core 10” OS.
b) Follow standard ICON procedures to connect to the public/outward-facing
Snowball/Fireball of choice. Use the “tun” interface option.
c) Test Internet connectivity
d) Insert the Mobile VPN Software (svn 9012) CD.
e) Run the Mobile VPN software installer as root:
su –
cd /media/<CDROM> && ./install.sh
3.(U) Usage
(S) Typical usage of the Mobile VPN capability is to task a Flytrap with a mission
that will perform VPN Link/Prosy actions where the VPN server is the “Mobile”
server. This section gives a brief overview on how to plan missions with VPN
actions. See the Cherry Blossom User’s Manual for more details.
SECRET
SECRET
issue the command ‘ifconfig’ and examine the IP address of the ‘tun’ interface). On
your CherryWeb workstation, configure a VPN server address for the Mobile VPN
server:
• From the CherryWeb menu pane, click Plan ->Exploits ->VPN Link/Proxy
• On the “Add a VPN Server for ‘VPN Link’ or ‘VPN Proxy All’ action” page,
enter a name for the Mobile VPN server in the ‘Proxy Name’ text box, enter
the public IP address of the Mobile VPN server in the ‘Proxy Address’ text
box, leave the value ‘80’ in the ‘Port’ field, and click ‘Create’.
SECRET
SECRET
4.(U) Caveats
(S) If the network interface of the Mobile VPN ICON workstation is modified after
the Mobile VPN server software is installed, or if the Mobile VPN software is
installed before the network interface has been configured, the workstation will
need to be rebooted and the server software reinstalled.
SECRET