US Reviews Possible Back Door In Juniper Networks Code

Megalith

24-bit/48kHz
Staff member
Joined
Aug 20, 2006
Messages
13,000
The company suggests that the vulnerability has not been exploited yet but that customers should, naturally, update their systems and apply the patched releases as soon as possible. Thanks to Rylan for the heads up.

Juniper warned customers on Thursday that it had uncovered "unauthorized code" in the software that runs its firewalls, saying it could be exploited to allow an attacker to unscramble encrypted communications. CNN reported Friday that the Federal Bureau of Investigation was probing the matter. An FBI representative declined comment to Reuters. A former Juniper security executive said the flaw appeared to be a "back door", a reference to rogue code secretly inserted into a product to enable attackers to eavesdrop on users.
 
Calm down, citizens, nothing to look at here, we're just keeping you safe from terrorism by inserting backdoors into everything, move along.
 
so this was either caught immediately (they didnt seem to specify, which makes me think this isnt the case.. because it's the best case and you'd want to claim this if it were) or it's been there and made it past testing, QA, etc?

dafuq? I smell some Palo Alto and Cisco salesmen having new material.
 
Based on the firmware versions listed as compromised, it has been in there for over 5 years. Oddly, the version I have on my SSG5 isn't in the range listed as bad. Several versions prior and after are. This makes the question of how the backdoor got in there even more interesting.

Juniper wants real money for a yearly firmware update agreement. More then the cost of a used unit. So far, this patch doesn't seem to be an exception to that rule.
 
Got in there very easily... compromised employee and either China, Russia, Israel or the Alphabet Agencies (more then likely in this case its our own Agencies)
 
Got in there very easily... compromised employee and either China, Russia, Israel or the Alphabet Agencies (more then likely in this case its our own Agencies)

my bet is on US agencies. That have had their fill of using this backdoor on foreign/US/ whoever companies for some time, and it's usefulness or their agreement with Juniper has come to an end.
 
You guys are not watching enough mainstream news.....it's obvious who this is.....North Korea hackers!
 
Back
Top