Argyll Free Press

Growing News Network

Tuesday, December 23, 2025
Log in
  • Business
  • Finance
  • Sports
  • Tech & Science
    • HP Envy 4500 Review
    • LG Optimus 170 Review
    • iPod Touch 6th Generation Review
    • HTC One M8 Accessories Set-up
    • Surrealist Games You Must Play
    • Hisense Sero 8 Review
    • Dell Latitude e7440 Review
    • HP Laserjet 1536dnf mfp Review
    • Garmin Fenix 2 Review
    • Skype Vs Viber
    • Best Video Conferencing Software
    • Sony mdr 1r Headphones Review
    • Canon Rebel t3i Review
    • Sennheiser Momentum 2-0 Review
  • Travel
  • Headlines
  • Health
  • United States

Juniper Networks Spy Code Story Continues

December 23, 2015 By Cristopher Hall Leave a Comment

Juniper Networks Logo and Motto in a building

New developments have occurred regarding the discovery of Juniper Networks spy code in its ScreenOS, that took place last week.

There were no less than two backdoors, not one. Discovered by non-Juniper Networks affiliated security and cryptography specialists in the past days.

The founder and CEO of Comsecuris, a German security company, said the more exact definition of what happened would be a “backdoored backdoor”.

Apart from the unauthorized code that Juniper Networks discovered last week in their ScreenOS, there was also a major vulnerability within the authorized code itself.

Because this code included a Random Number Generator (RNG) called Dual_EC_DRBG as the basis of its encryption for NetScreen devices. And this RNG was widely known to be a major security risk ever since 2007 when two Microsoft researchers, Dan Shumow and Neils Ferguson, exposed its backdoor potential via Q, one of the constants it uses.

What’s more interesting? Though it lost it’s NIST (US National Institute of Standards and Technology) approval then, it was initially standardized and approved by NIST after it was strongly promoted by… none other than the NSA. Who also happened to develop Dual_EC_DRBG.

Take into account that the New York Times reported in 2013 (based on Edward Snowden leaks) that NSA put the vulnerability inside this RNG on purpose and it paints a pretty picture.

Even more interesting is that Juniper Networks have admitted that they consciously used Dual_EC_DRBG, despite knowing of its security risk, because they took other countermeasures to nullify it.

Namely  using “self-generated basis points” instead of the P and Q constants, supposed to be points on an elliptic curve and, on top of that, using the output of Dual_EC_DRBG (the random number) as an input for another RNG called FIPS/ANSI X.9.31.

This latter RNG’s output was supposed to be used for the encryption operations. As described by Juniper Networks, the Q vulnerability (planted there by NSA or whoever did) would have indeed been useless.

But here’s the thing. The code that was supposed to pass the Dual_EC_DRGB result to the FIPS/ANSI X.9.31 RNG had an error in it. Hence, it failed and didn’t pass anything. Hence, FIPS/ANSI X.9.31 never ran and was completely useless, as pointed out by Willem Pinckaers, the security researcher who discovered this error. Which prompted Weinmann to say: backdoored backdoor.

This comes at a time when there is an increase of state-involvement in private companies’ data management and amid a push from governments and intelligence agencies to force big companies to implement backdoors for lawful use by them in investigations.

The Juniper Networks example should serve as a warning that hackers can use such backdoors too!

The good news: though real, as confirmed by the hard coded hidden password discovered by the researchers, the administrative rights vulnerability is not as extensive as previously announced by Juniper Networks.

It only affects ScreenOS versions 6.3.0r17 – 6.3.0r20.

The VPN decryption one affects versions 6.2.0r15 – 6.2.0r18 and 6.3.0r12 – 6.3.0r20.

Image source: 1.

Filed Under: Headlines Tagged With: Juniper Networks, Juniper Networks spy code, Juniper Networks vulnerabilities, Juniper Networks vulnerability, NetScreen vulnerabilities, NetScreen vulnerability, ScreenOS vulnerabilities, ScreenOS vulnerability, security, vulnerabilities, vulnerability

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 10 other subscribers

Recent Articles

police handcuffs man

German Man Probed In Poisoning That Killed 21 Employees Since 2000

June 29, 2018 By Kenneth Scott Leave a Comment

Chicken wings bar

Intoxicated South Carolina Man Punches Waitress Who Refused to Serve Him Alcohol

June 29, 2018 By Karen Jackson Leave a Comment

gaming

New Zealand gamer Who Flew Halfway Across The World for Virginia Teen Gets Shots By Her Mother

June 28, 2018 By Cristopher Hall Leave a Comment

party

Former Virginia Tech Freshman Sentenced to 50 Years in Prison for Stabbing a Girl to Death

June 28, 2018 By Roxanne Briean Leave a Comment

bonfire

British Couple Sentenced to Life in Prison for Torturing and Murdering French Nanny

June 27, 2018 By Deborah Campbell Leave a Comment

pay phone

Texas Father of Girl Disappeared in the 80s Ignored by Authorities

June 26, 2018 By Cristopher Hall Leave a Comment

bottled water

San Francisco Woman Threatened to Call Police on Girl Who Sold Ice Water for Disneyland Trip

June 25, 2018 By Roxanne Briean Leave a Comment

Maplewood Park

Missouri Man Robbed by Date and Accomplice in Park

June 22, 2018 By Nancy Young Leave a Comment

coding

New York Man Sentenced in Cyberstalking Former Girlfriend, Mailing Drugs to Her Dorm

June 22, 2018 By Deborah Campbell Leave a Comment

headphones

Bose Poised to Launch Sleepbuds, In-Ear Headphones That Help You Sleep

June 21, 2018 By Nancy Young Leave a Comment

Police light

Intoxicated Female Driver in Custody for Pulling Arresting Officer by the Hair

June 21, 2018 By Kenneth Scott Leave a Comment

kitchen

Restaurant Manager Arrested and Charged in Shooting Death of Co-Worker over Negative Yelp Reviews

June 20, 2018 By Karen Jackson Leave a Comment

plastic container

Pennsylvania Couple Charged in Violent Death of Infant Discovered Buried in Cat Litter

June 19, 2018 By Cristopher Hall Leave a Comment

tailpipe

Minnesota Teen Gets Head Stuck In Oversized Tailpipe Winstock Music Festival

June 18, 2018 By Karen Jackson Leave a Comment

Pages

  • About Us
  • Contact us
  • Privacy Policy
  • Privacy Policy GDPR
  • Staff
  • Terms and Conditions

Recent Posts

  • German Man Probed In Poisoning That Killed 21 Employees Since 2000 June 29, 2018
  • Intoxicated South Carolina Man Punches Waitress Who Refused to Serve Him Alcohol June 29, 2018
  • New Zealand gamer Who Flew Halfway Across The World for Virginia Teen Gets Shots By Her Mother June 28, 2018
  • Former Virginia Tech Freshman Sentenced to 50 Years in Prison for Stabbing a Girl to Death June 28, 2018
  • British Couple Sentenced to Life in Prison for Torturing and Murdering French Nanny June 27, 2018
  • Texas Father of Girl Disappeared in the 80s Ignored by Authorities June 26, 2018
  • San Francisco Woman Threatened to Call Police on Girl Who Sold Ice Water for Disneyland Trip June 25, 2018

Categories

  • Business
  • Entertainment
  • Finance
  • Headlines
  • Health
  • Life
  • Nature
  • Science
  • Sports
  • Tech & Science
  • Travel
  • Uncategorized
  • United States
  • World

Copyright © 2025 ArgyllFreePress.com
About · Privacy Policy · Terms of Use · Contact