Argyll Free Press

Growing News Network

Tuesday, April 28, 2026
Log in
  • Business
  • Finance
  • Sports
  • Tech & Science
    • HP Envy 4500 Review
    • LG Optimus 170 Review
    • iPod Touch 6th Generation Review
    • HTC One M8 Accessories Set-up
    • Surrealist Games You Must Play
    • Hisense Sero 8 Review
    • Dell Latitude e7440 Review
    • HP Laserjet 1536dnf mfp Review
    • Garmin Fenix 2 Review
    • Skype Vs Viber
    • Best Video Conferencing Software
    • Sony mdr 1r Headphones Review
    • Canon Rebel t3i Review
    • Sennheiser Momentum 2-0 Review
  • Travel
  • Headlines
  • Health
  • United States

Juniper Networks Spy Code Story Continues

December 23, 2015 By Cristopher Hall Leave a Comment

Juniper Networks Logo and Motto in a building

New developments have occurred regarding the discovery of Juniper Networks spy code in its ScreenOS, that took place last week.

There were no less than two backdoors, not one. Discovered by non-Juniper Networks affiliated security and cryptography specialists in the past days.

The founder and CEO of Comsecuris, a German security company, said the more exact definition of what happened would be a “backdoored backdoor”.

Apart from the unauthorized code that Juniper Networks discovered last week in their ScreenOS, there was also a major vulnerability within the authorized code itself.

Because this code included a Random Number Generator (RNG) called Dual_EC_DRBG as the basis of its encryption for NetScreen devices. And this RNG was widely known to be a major security risk ever since 2007 when two Microsoft researchers, Dan Shumow and Neils Ferguson, exposed its backdoor potential via Q, one of the constants it uses.

What’s more interesting? Though it lost it’s NIST (US National Institute of Standards and Technology) approval then, it was initially standardized and approved by NIST after it was strongly promoted by… none other than the NSA. Who also happened to develop Dual_EC_DRBG.

Take into account that the New York Times reported in 2013 (based on Edward Snowden leaks) that NSA put the vulnerability inside this RNG on purpose and it paints a pretty picture.

Even more interesting is that Juniper Networks have admitted that they consciously used Dual_EC_DRBG, despite knowing of its security risk, because they took other countermeasures to nullify it.

Namely  using “self-generated basis points” instead of the P and Q constants, supposed to be points on an elliptic curve and, on top of that, using the output of Dual_EC_DRBG (the random number) as an input for another RNG called FIPS/ANSI X.9.31.

This latter RNG’s output was supposed to be used for the encryption operations. As described by Juniper Networks, the Q vulnerability (planted there by NSA or whoever did) would have indeed been useless.

But here’s the thing. The code that was supposed to pass the Dual_EC_DRGB result to the FIPS/ANSI X.9.31 RNG had an error in it. Hence, it failed and didn’t pass anything. Hence, FIPS/ANSI X.9.31 never ran and was completely useless, as pointed out by Willem Pinckaers, the security researcher who discovered this error. Which prompted Weinmann to say: backdoored backdoor.

This comes at a time when there is an increase of state-involvement in private companies’ data management and amid a push from governments and intelligence agencies to force big companies to implement backdoors for lawful use by them in investigations.

The Juniper Networks example should serve as a warning that hackers can use such backdoors too!

The good news: though real, as confirmed by the hard coded hidden password discovered by the researchers, the administrative rights vulnerability is not as extensive as previously announced by Juniper Networks.

It only affects ScreenOS versions 6.3.0r17 – 6.3.0r20.

The VPN decryption one affects versions 6.2.0r15 – 6.2.0r18 and 6.3.0r12 – 6.3.0r20.

Image source: 1.

The following two tabs change content below.
  • Bio
  • Latest Posts

Cristopher Hall

Christopher Hall completed his studies at the California Institute of Technology, Caltech, with a degree in Engineering and Applied Science. That was three years ago. At present he is working as a Computation and Neural Systems engineer in Ontario. He used to write tech reviews and overviews for several small online publications before he joined the ArgyllFreePress team. Christopher is always scouring the internet for fresh tech news and anything related to gadgets, smart-phones, tablets and laptops.

Latest posts by Cristopher Hall (see all)

  • New Zealand gamer Who Flew Halfway Across The World for Virginia Teen Gets Shots By Her Mother - June 28, 2018
  • Texas Father of Girl Disappeared in the 80s Ignored by Authorities - June 26, 2018
  • Pennsylvania Couple Charged in Violent Death of Infant Discovered Buried in Cat Litter - June 19, 2018

Filed Under: Headlines Tagged With: Juniper Networks, Juniper Networks spy code, Juniper Networks vulnerabilities, Juniper Networks vulnerability, NetScreen vulnerabilities, NetScreen vulnerability, ScreenOS vulnerabilities, ScreenOS vulnerability, security, vulnerabilities, vulnerability

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 11 other subscribers

Recent Articles

police handcuffs man

German Man Probed In Poisoning That Killed 21 Employees Since 2000

June 29, 2018 By Kenneth Scott Leave a Comment

Chicken wings bar

Intoxicated South Carolina Man Punches Waitress Who Refused to Serve Him Alcohol

June 29, 2018 By Karen Jackson Leave a Comment

gaming

New Zealand gamer Who Flew Halfway Across The World for Virginia Teen Gets Shots By Her Mother

June 28, 2018 By Cristopher Hall Leave a Comment

party

Former Virginia Tech Freshman Sentenced to 50 Years in Prison for Stabbing a Girl to Death

June 28, 2018 By Roxanne Briean Leave a Comment

bonfire

British Couple Sentenced to Life in Prison for Torturing and Murdering French Nanny

June 27, 2018 By Deborah Campbell Leave a Comment

pay phone

Texas Father of Girl Disappeared in the 80s Ignored by Authorities

June 26, 2018 By Cristopher Hall Leave a Comment

bottled water

San Francisco Woman Threatened to Call Police on Girl Who Sold Ice Water for Disneyland Trip

June 25, 2018 By Roxanne Briean Leave a Comment

Maplewood Park

Missouri Man Robbed by Date and Accomplice in Park

June 22, 2018 By Nancy Young Leave a Comment

coding

New York Man Sentenced in Cyberstalking Former Girlfriend, Mailing Drugs to Her Dorm

June 22, 2018 By Deborah Campbell Leave a Comment

headphones

Bose Poised to Launch Sleepbuds, In-Ear Headphones That Help You Sleep

June 21, 2018 By Nancy Young Leave a Comment

Police light

Intoxicated Female Driver in Custody for Pulling Arresting Officer by the Hair

June 21, 2018 By Kenneth Scott Leave a Comment

kitchen

Restaurant Manager Arrested and Charged in Shooting Death of Co-Worker over Negative Yelp Reviews

June 20, 2018 By Karen Jackson Leave a Comment

plastic container

Pennsylvania Couple Charged in Violent Death of Infant Discovered Buried in Cat Litter

June 19, 2018 By Cristopher Hall Leave a Comment

tailpipe

Minnesota Teen Gets Head Stuck In Oversized Tailpipe Winstock Music Festival

June 18, 2018 By Karen Jackson Leave a Comment

Pages

  • About Us
  • Contact us
  • Privacy Policy
  • Privacy Policy GDPR
  • Staff
  • Terms and Conditions

Recent Posts

  • German Man Probed In Poisoning That Killed 21 Employees Since 2000 June 29, 2018
  • Intoxicated South Carolina Man Punches Waitress Who Refused to Serve Him Alcohol June 29, 2018
  • New Zealand gamer Who Flew Halfway Across The World for Virginia Teen Gets Shots By Her Mother June 28, 2018
  • Former Virginia Tech Freshman Sentenced to 50 Years in Prison for Stabbing a Girl to Death June 28, 2018
  • British Couple Sentenced to Life in Prison for Torturing and Murdering French Nanny June 27, 2018
  • Texas Father of Girl Disappeared in the 80s Ignored by Authorities June 26, 2018
  • San Francisco Woman Threatened to Call Police on Girl Who Sold Ice Water for Disneyland Trip June 25, 2018

Related Articles

  • new emails hillary clinton server case

    FBI Uncovers New Emails in Hillary Clinton Server Case

    Oct 28, 2016
  • Brendan Iribe Twitter

    Brendan Iribe’s Twitter Account Hacked

    Jul 1, 2016
  • closeup of graduation cap and cash roll

    Student Loan Debt Piles Up at Record Pace

    Jun 8, 2016
  • extraordinary light show whenever solar storms collide with their magnetospheres

    Northern Lights Arise on Planet Jupiter

    Mar 23, 2016
  • an interview with the humanoid robot named Sophia

    Sophia the Robot Agrees to Destroy All Humans

    Mar 23, 2016
  • concept of Wi-Fi calling was first introduced back in October

    AT&T Expands Its Wi-Fi Calling Service to International

    Mar 23, 2016
  • The tragedy that hit Brussels

    Facebook Quick to Put Some Minds at Ease with the Safety Check Feature

    Mar 22, 2016
  • Best Graphics Cards 2016 Guide

    The Best Graphics Cards 2016 Guide – Preparing for A Long Year of Gaming

    Jan 29, 2016
  • Java Browser Plugin Is Finally Killed by Oracle

    Jan 28, 2016
  • DISH vs DirecTV

    DISH vs DirecTV – A Complete Guide to Satellite Television

    Jan 28, 2016

Categories

  • Business
  • Entertainment
  • Finance
  • Headlines
  • Health
  • Life
  • Nature
  • Science
  • Sports
  • Tech & Science
  • Travel
  • Uncategorized
  • United States
  • World

Copyright © 2026 ArgyllFreePress.com
About · Privacy Policy · Terms of Use · Contact