Networking-Forums.com

Professional Discussions => Security => Topic started by: wintermute000 on December 18, 2015, 04:14:12 AM

Title: Netscreens: backdoor discovered
Post by: wintermute000 on December 18, 2015, 04:14:12 AM
https://threatpost.com/juniper-finds-backdoor-that-decrypts-vpn-traffic/115663/
Title: Re: Netscreens: backdoor discovered
Post by: icecream-guy on December 18, 2015, 06:38:13 AM
here too...
http://www.networkworld.com/article/3016992/security/juniper-firewalls-compromised-by-spy-code-what-you-need-to-know.html
Title: Re: Netscreens: backdoor discovered
Post by: deanwebb on December 18, 2015, 08:56:06 AM
Yep. I've already passed that alert on up my command chain. I expect an upgrade sometime next week, probably on Christmas Day, when everything's turned off.
Title: Re: Netscreens: backdoor discovered
Post by: wintermute000 on December 20, 2015, 04:57:00 AM
It gets better. The patch reveals another backdoor (not FEEDTHROUGH)

http://www.wired.com/2015/12/juniper-networks-hidden-backdoors-show-the-risk-of-government-backdoors/

Title: Re: Netscreens: backdoor discovered
Post by: deanwebb on December 20, 2015, 08:03:03 AM
Quote from: wintermute000 on December 20, 2015, 04:57:00 AM
It gets better. The patch reveals another backdoor (not FEEDTHROUGH)

http://www.wired.com/2015/12/juniper-networks-hidden-backdoors-show-the-risk-of-government-backdoors/



Prins says the larger concern now is whether other firewall manufacturers have been compromised in a similar manner. "I hope that other vendors like Cisco and Checkpoint are also now starting a process to review their code to see if they have backdoors inserted," he said.

:jackie-chan:

They DAMN SURE better be starting that review process, and with all speed... My guess is if they're not able to patch it - and this could be due to other government entanglements - then they'll say nothing or dismiss it like, "That was Juniper's problem, not ours."

But if they can patch it, it may be because they're working with the same actors that introduced the first backdoor and that the patch takes care of everything the vulnerability researchers are going to be looking for... and then, another patch comes out later on with a different sort of backdoor, designed to evade current testing methods.

:notthefirewall:
Title: Re: Netscreens: backdoor discovered
Post by: SimonV on December 21, 2015, 06:09:46 AM
The password is out in the open:

https://community.rapid7.com/community/infosec/blog/2015/12/20/cve-2015-7755-juniper-screenos-authentication-backdoor


https://pbs.twimg.com/tweet_video/CWuoey7XIAA3T2M.mp4
Title: Re: Netscreens: backdoor discovered
Post by: deanwebb on December 21, 2015, 09:37:11 AM
Waiting for the major financial firm to announce it got hacked that way in 3... 2...
Title: Re: Netscreens: backdoor discovered
Post by: SimonV on December 21, 2015, 12:16:04 PM
No doubt, just look at the amount of devices Shodan has indexed:

https://www.shodan.io/search?query=netscreen
Title: Re: Netscreens: backdoor discovered
Post by: DanC on December 21, 2015, 02:20:57 PM
Quote from: SimonV on December 21, 2015, 06:09:46 AM

https://pbs.twimg.com/tweet_video/CWuoey7XIAA3T2M.mp4

:rofl:
Title: Re: Netscreens: backdoor discovered
Post by: routerdork on December 21, 2015, 04:59:45 PM
Quote from: DanC on December 21, 2015, 02:20:57 PM
Quote from: SimonV on December 21, 2015, 06:09:46 AM

https://pbs.twimg.com/tweet_video/CWuoey7XIAA3T2M.mp4

:rofl:
lol