Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

Juniper back door

  • 22-12-2015 11:27am
    #1
    Registered Users, Registered Users 2 Posts: 37,485 ✭✭✭✭


    Looks like someone (probably the NSA in fairness) has back doored Juniper devices. The password is very cleverly obfuscated to look like code.

    More details here. If you use Juniper devices in your network though, you should be patching ASAP.

    The password they hid in the code is:
    <<< %s(un='%s') = %u, "
    

    Sneaky, but clever. It reminds me of that annual competition to back door code sneakily. Last years winner was particularly impressive. Can't remember the details of it though. Anyone else?


Comments

  • Closed Accounts Posts: 18,966 ✭✭✭✭syklops


    Khannie wrote: »
    Looks like someone (probably the NSA in fairness) has back doored Juniper devices. The password is very cleverly obfuscated to look like code.

    More details here. If you use Juniper devices in your network though, you should be patching ASAP.

    The password they hid in the code is:
    <<< %s(un='%s') = %u, "
    

    Sneaky, but clever. It reminds me of that annual competition to back door code sneakily. Last years winner was particularly impressive. Can't remember the details of it though. Anyone else?

    You mean the hide the backdoor contest at DefCon? Some info here

    I've not found the winning entry yet though. Maybe they don't offically release them.

    Tbh, its not something I ever thought abou competing in, but as you've pointed out, its just about being sneaky. Definitely something to consider for next year.


  • Registered Users, Registered Users 2 Posts: 51,054 ✭✭✭✭Professey Chin


    Lovely. No Juniper here but I can think of a few large agencies with sensitive data using them.


  • Registered Users, Registered Users 2 Posts: 37,485 ✭✭✭✭Khannie


    syklops wrote: »
    You mean the hide the backdoor contest at DefCon? Some info here

    That does ring a bell. I have a feeling it was earlier in the year than defcon, but it's only a feeling. I did see the winning entry and I was *blown away* by it. I actually thought the runner up might have been just as good and possibly better. It made for a very disturbing but enjoyable read at the time. We tweeted about it so I'll see if I can dig that out.


  • Registered Users, Registered Users 2 Posts: 3,735 ✭✭✭Stuxnet


    Excellent write up today on WIRED about it

    Researchers Solve Juniper Backdoor Mystery; Signs Point to NSA


  • Closed Accounts Posts: 1,460 ✭✭✭DipStick McSwindler


    This post has been deleted.


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 37,485 ✭✭✭✭Khannie


    Stuxnet wrote: »
    Excellent write up today on WIRED about it

    Researchers Solve Juniper Backdoor Mystery; Signs Point to NSA

    That's a good read alright. Thanks.


  • Closed Accounts Posts: 18,966 ✭✭✭✭syklops


    Oh the irony :D

    You know what I meant.


  • Closed Accounts Posts: 3,006 ✭✭✭_Tombstone_


    Junipers 3 year old own back door that some else made use of by some accounts.


  • Registered Users, Registered Users 2 Posts: 51,054 ✭✭✭✭Professey Chin


    Keeping with the trend looks like theres an SSH one in Fortigate appliances too.

    http://thehackernews.com/2016/01/fortinet-firewall-password-hack.html

    Less risky since most would have SSH access locked down and its patched in newer versions. Seems to be more of an error then a malicious backdoor too.


  • Closed Accounts Posts: 18,966 ✭✭✭✭syklops


    Keeping with the trend looks like theres an SSH one in Fortigate appliances too.

    http://thehackernews.com/2016/01/fortinet-firewall-password-hack.html

    Less risky since most would have SSH access locked down and its patched in newer versions. Seems to be more of an error then a malicious backdoor too.

    News worthy of its own thread.


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 51,054 ✭✭✭✭Professey Chin


    Good point. Ill get moving


Advertisement