DaemonForums  

Go Back   DaemonForums > DaemonForums.org > News

News News regarding BSD and related.

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 18th December 2015
e1-531g e1-531g is offline
ISO Quartermaster
 
Join Date: Mar 2014
Posts: 628
Default Backdoor in NetScreen firewalls gives attackers admin access, VPN decrypt ability.

http://arstechnica.com/security/2015...d-vpn-traffic/
https://forums.juniper.net/t5/Securi...OS/ba-p/285554

Quote:
An operating system used to manage firewalls sold by Juniper Networks contains unauthorized code that surreptitiously decrypts traffic sent through virtual private networks, officials from the company warned Thursday.

It's not clear how the code got there or how long it has been there. An advisory published by the company said that NetScreen firewalls using ScreenOS 6.2.0r15 through 6.2.0r18 and 6.3.0r12 through 6.3.0r20 are affected and require immediate patching. Release notes published by Juniper suggest the earliest vulnerable versions date back to at least 2012 and possibly earlier. There's no evidence right now that the backdoor was put in other Juniper OSes or devices.

"During a recent internal code review, Juniper discovered unauthorized code in ScreenOS that could allow a knowledgeable attacker to gain administrative access to NetScreen devices and to decrypt VPN connections," Juniper Chief Information officer Bob Worrall wrote. "Once we identified these vulnerabilities, we launched an investigation into the matter, and worked to develop and issue patched releases for the latest versions of ScreenOS."
Reply With Quote
  #2   (View Single Post)  
Old 18th December 2015
Oko's Avatar
Oko Oko is offline
Rc.conf Instructor
 
Join Date: May 2008
Location: Kosovo, Serbia
Posts: 1,102
Default

I owner of this is related to well known Jail vulnerabilities which can be used to unlock Playstation 4?
Reply With Quote
  #3   (View Single Post)  
Old 18th December 2015
rons's Avatar
rons rons is offline
Snoozing
 
Join Date: Oct 2015
Posts: 69
Default

I know Juniper uses some BSD stuff. I wonder if Netscreen or ScreenOS is related in any way?
Reply With Quote
  #4   (View Single Post)  
Old 18th December 2015
e1-531g e1-531g is offline
ISO Quartermaster
 
Join Date: Mar 2014
Posts: 628
Default

https://www.juniper.net/techpubs/sof...S-glossary.pdf
Quote:
This product includes FreeBSD software developed by the University of California, Berkeley, and its contributors. All of the documentation and software included in the 4.4BSD and 4.4BSD-Lite.
Via Arstechnica:
Quote:
Release notes published by Juniper suggest the earliest vulnerable versions date back to at least 2012 and possibly earlier.
Reply With Quote
  #5   (View Single Post)  
Old 19th December 2015
kpa kpa is offline
Port Guard
 
Join Date: Jul 2015
Posts: 18
Default

According to a post on the FreeBSD forums the supposedly vulnerable ScreenOS versions are not based on *BSD and ScreenOS has been end of life for seven years to boot...
Reply With Quote
  #6   (View Single Post)  
Old 19th December 2015
e1-531g e1-531g is offline
ISO Quartermaster
 
Join Date: Mar 2014
Posts: 628
Default

@kpa
According to link in post ScreenOS 6.3 (one of vulnerable versions) includes FreeBSD software. I don't know how many but it have some *BSD code. Maybe 5%, maybe 90%.
And seven years is not for sale, but support continues. It is firewall so often one doesn't need to upgrade it each year and probably doesn't even want to.
Reply With Quote
Reply

Tags
juniper firewall, screenos


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Backdoor in wireless DSL routers lets attacker reset router, get admin J65nko News 3 6th January 2014 12:30 AM
SSH private key gives attackers access to BIG-IP appliances J65nko News 0 13th June 2012 12:55 PM
Apache hole allows attackers to access internal servers J65nko News 0 6th October 2011 05:50 PM
pf: Does pf have the ability to src-track created/established connections? gen2ly OpenBSD Security 3 27th February 2009 03:10 PM
Couple of network questions (NAT, firewalls) ivanatora FreeBSD General 10 21st July 2008 05:26 PM


All times are GMT. The time now is 06:46 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick