Knowledge (XXG)

ScreenOS

Source 📝

1626: 1616: 163:
it created would allow sophisticated hackers to control the firewall of un-patched Juniper Netscreen products and decrypt network traffic. At least one of the backdoors appeared likely to have been the effort of a governmental interest. There was speculation in the security field about whether it was
194:
against the following ScreenOS devices: NS5gt, N25, NS50, NS500, NS204, NS208, NS5200, NS5000, SSG5, SSG20, SSG140, ISG 1000, ISG 2000. The exploit capabilities seem consistent with the program codenamed FEEDTROUGH.
174:
speculated that the lack of details that were disclosed and the intentional use of a random number generator with known security flaws could suggest that it was planted intentionally.
723: 1664: 690: 422: 127: 449: 1620: 716: 580: 1657: 365: 187: 1828: 1630: 709: 1823: 1833: 1802: 1650: 1398: 1433: 1703: 1210: 398: 1387: 442: 347: 1485: 1247: 1843: 875: 788: 58: 1478: 732: 104: 1838: 1358: 1125: 993: 893: 435: 107: 1733: 1673: 1510: 1472: 1178: 183: 165: 1346: 905: 829: 137: 1517: 1440: 616: 159:
announced that it had found unauthorized code in ScreenOS that had been there since August 2012. The two
1204: 1096: 595: 1609: 1404: 1020: 160: 144: 1506: 1002: 610: 1553: 1221: 529: 518: 472: 122:
Beside transport level security ScreenOS also integrates these flow management applications:
1769: 1305: 741: 649: 634: 628: 513: 508: 503: 498: 458: 170: 156: 111: 78: 35: 1688: 1136: 816: 622: 394: 168:. Many in the security industry praised Juniper for being transparent about the breach. 1558: 1069: 948: 943: 658: 482: 390: 1817: 1314: 1062: 933: 701: 643: 1789: 1764: 1578: 1573: 920: 881: 477: 1642: 1774: 1698: 1601: 1563: 1458: 1328: 601: 366:"New Discovery Around Juniper Backdoor Raises More Questions About the Company" 1708: 1545: 1426: 1293: 589: 30: 1693: 1568: 1446: 1420: 1340: 1164: 954: 762: 1759: 1713: 1392: 1334: 1041: 938: 899: 868: 777: 551: 91: 1784: 1723: 1718: 1535: 1529: 1496: 1491: 1381: 1352: 1321: 1299: 1236: 1197: 1172: 1151: 1105: 1083: 822: 1779: 1373: 1276: 1262: 1250: 1118: 1111: 1076: 1035: 1029: 849: 840: 804: 782: 427: 399:"NSA Helped British Spies Find Security Holes In Juniper Firewalls" 1743: 1465: 1269: 978: 887: 752: 561: 556: 131: 1738: 1523: 1416: 1230: 1145: 1009: 972: 771: 1646: 705: 431: 1410: 1253: 1188: 1053: 810: 151:
Possible NSA backdoor and 2015 "Unauthorized Code" incident
110:
for the NetScreen range of hardware firewall devices from
136:
IP packet inspection (low level) for protection against
1752: 1681: 1544: 1505: 1286: 1246: 1220: 1187: 1163: 1135: 1095: 1052: 1019: 992: 965: 919: 860: 839: 761: 751: 740: 683: 576: 544: 491: 465: 87: 77: 57: 49: 41: 29: 343: 341: 691:Juniper Networks Technical Certification Program 1658: 717: 443: 359: 357: 355: 8: 24: 1665: 1651: 1643: 1615: 926: 758: 748: 724: 710: 702: 450: 436: 428: 202: 23: 337: 7: 664:Brilliant Telecommunications ('11) 14: 1704:Dell Networking Operating System 1625: 1624: 1614: 1211:Transaction Processing Facility 423:ScreenOS Software Documentation 364:Zetter, Kim (27 October 2008). 1: 348:Release Notes 6.3.0r27 Rev 01 63:6.3.0r27 / 23 April 2019 640:Acorn Packet Solutions ('05) 126:IP gateway VPN management – 1829:Real-time operating systems 789:Multi-Environment Real-Time 733:Real-time operating systems 1860: 1824:Embedded operating systems 192:current exploit capability 16:Real-time operating system 1834:Network operating systems 1798: 1674:Network operating systems 1587: 929: 894:Operating System Embedded 315: 301: 287: 273: 259: 245: 231: 219: 214: 211: 208: 205: 108:embedded operating system 1179:Windows Embedded Compact 1518:Robot Operating System 670:Contrail Systems ('12) 667:Mykonos Software ('12) 617:NetScreen Technologies 655:SMobile Systems ('10) 596:Pacific Advantage Ltd 65:; 5 years ago 1610:Open-source software 1021:Java virtual machine 397:(23 December 2015). 145:network segmentation 1844:Computer networking 607:Nexsi Systems ('02) 186:document says that 143:Virtualization for 94:(on later hardware) 26: 611:Unisphere Networks 155:In December 2015, 1811: 1810: 1640: 1639: 1368: 1367: 1222:Texas Instruments 988: 987: 915: 914: 699: 698: 473:Shaygan Kheradpir 329: 328: 311:18 December 2007 206:ScreenOS version 98: 97: 1851: 1839:Juniper Networks 1667: 1660: 1653: 1644: 1628: 1627: 1618: 1617: 1306:ERIKA Enterprise 994:Capability-based 927: 759: 749: 726: 719: 712: 703: 650:Ankeena Networks 635:Redline Networks 629:Peribit Networks 602:Micro Magic Inc. 459:Juniper Networks 452: 445: 438: 429: 410: 409: 407: 405: 387: 381: 380: 378: 376: 361: 350: 345: 325:31 October 2007 308:18 December 2006 305:18 December 2003 297:22 October 2008 269:24 October 2009 203: 157:Juniper Networks 112:Juniper Networks 73: 71: 66: 36:Juniper Networks 27: 21:Operating system 1859: 1858: 1854: 1853: 1852: 1850: 1849: 1848: 1814: 1813: 1812: 1807: 1794: 1748: 1689:AlliedWare Plus 1677: 1671: 1641: 1636: 1613: 1583: 1540: 1501: 1364: 1282: 1242: 1216: 1183: 1159: 1131: 1091: 1048: 1015: 984: 961: 911: 856: 835: 817:Real-Time Linux 743: 736: 730: 700: 695: 679: 673:Webscreen ('13) 623:Kagoor Networks 578: 572: 545:System software 540: 487: 461: 456: 419: 414: 413: 403: 401: 395:Glenn Greenwald 389: 388: 384: 374: 372: 363: 362: 353: 346: 339: 334: 322:31 October 2006 294:22 October 2007 291:22 October 2004 266:24 October 2008 263:24 October 2005 212:End of Support 201: 180: 153: 120: 69: 67: 64: 22: 17: 12: 11: 5: 1857: 1855: 1847: 1846: 1841: 1836: 1831: 1826: 1816: 1815: 1809: 1808: 1806: 1805: 1799: 1796: 1795: 1793: 1792: 1787: 1782: 1777: 1772: 1767: 1762: 1756: 1754: 1750: 1749: 1747: 1746: 1741: 1736: 1731: 1726: 1721: 1716: 1711: 1706: 1701: 1696: 1691: 1685: 1683: 1679: 1678: 1672: 1670: 1669: 1662: 1655: 1647: 1638: 1637: 1635: 1634: 1605: 1597: 1595:= discontinued 1588: 1585: 1584: 1582: 1581: 1576: 1571: 1566: 1561: 1559:David Cheriton 1556: 1550: 1548: 1542: 1541: 1539: 1533: 1527: 1521: 1515: 1513: 1503: 1502: 1500: 1499: 1494: 1489: 1483: 1469: 1462: 1455: 1450: 1444: 1437: 1430: 1424: 1414: 1408: 1402: 1396: 1390: 1385: 1378: 1369: 1366: 1365: 1363: 1362: 1356: 1350: 1344: 1338: 1332: 1326: 1318: 1312: 1309: 1303: 1297: 1290: 1288: 1284: 1283: 1281: 1280: 1273: 1266: 1258: 1256: 1244: 1243: 1241: 1240: 1237:TI-RTOS Kernel 1234: 1226: 1224: 1218: 1217: 1215: 1214: 1208: 1201: 1193: 1191: 1185: 1184: 1182: 1181: 1176: 1169: 1167: 1161: 1160: 1158: 1157: 1141: 1139: 1133: 1132: 1130: 1129: 1123: 1115: 1109: 1102: 1100: 1093: 1092: 1090: 1089: 1088: 1087: 1080: 1073: 1070:Concurrent DOS 1058: 1056: 1050: 1049: 1047: 1046: 1025: 1023: 1017: 1016: 1014: 1013: 1007: 998: 996: 990: 989: 986: 985: 983: 982: 976: 969: 967: 963: 962: 960: 959: 958: 957: 952: 951:(organization) 949:T-Engine Forum 946: 944:Micro T-Kernel 936: 930: 924: 917: 916: 913: 912: 910: 909: 903: 897: 891: 885: 879: 873: 864: 862: 858: 857: 855: 854: 845: 843: 837: 836: 834: 833: 826: 820: 814: 808: 801: 785: 780: 775: 767: 765: 756: 746: 738: 737: 731: 729: 728: 721: 714: 706: 697: 696: 694: 693: 687: 685: 681: 680: 678: 677: 674: 671: 668: 665: 662: 659:Altor Networks 656: 653: 647: 641: 638: 632: 626: 620: 614: 608: 605: 599: 593: 586: 584: 574: 573: 571: 570: 565: 559: 554: 548: 546: 542: 541: 539: 538: 535: 532: 527: 524: 521: 516: 511: 506: 501: 495: 493: 489: 488: 486: 485: 483:Pradeep Sindhu 480: 475: 469: 467: 463: 462: 457: 455: 454: 447: 440: 432: 426: 425: 418: 417:External links 415: 412: 411: 391:Ryan Gallagher 382: 351: 336: 335: 333: 330: 327: 326: 323: 320: 317: 313: 312: 309: 306: 303: 299: 298: 295: 292: 289: 285: 284: 281: 278: 275: 271: 270: 267: 264: 261: 257: 256: 253: 250: 247: 243: 242: 241:19 April 2011 239: 236: 233: 229: 228: 226: 224: 221: 217: 216: 213: 210: 207: 200: 197: 182:A 2011 leaked 179: 176: 152: 149: 148: 147: 141: 134: 119: 116: 96: 95: 89: 85: 84: 81: 75: 74: 61: 59:Latest release 55: 54: 51: 47: 46: 43: 39: 38: 33: 20: 15: 13: 10: 9: 6: 4: 3: 2: 1856: 1845: 1842: 1840: 1837: 1835: 1832: 1830: 1827: 1825: 1822: 1821: 1819: 1804: 1801: 1800: 1797: 1791: 1788: 1786: 1783: 1781: 1778: 1776: 1773: 1771: 1770:Cumulus Linux 1768: 1766: 1763: 1761: 1758: 1757: 1755: 1751: 1745: 1742: 1740: 1737: 1735: 1732: 1730: 1727: 1725: 1722: 1720: 1717: 1715: 1712: 1710: 1707: 1705: 1702: 1700: 1697: 1695: 1692: 1690: 1687: 1686: 1684: 1680: 1675: 1668: 1663: 1661: 1656: 1654: 1649: 1648: 1645: 1633: 1632: 1623: 1622: 1612: 1611: 1606: 1604: 1603: 1598: 1596: 1593: 1590: 1589: 1586: 1580: 1577: 1575: 1572: 1570: 1567: 1565: 1562: 1560: 1557: 1555: 1552: 1551: 1549: 1547: 1543: 1537: 1534: 1531: 1528: 1525: 1522: 1519: 1516: 1514: 1512: 1508: 1504: 1498: 1495: 1493: 1490: 1487: 1484: 1481: 1480: 1475: 1474: 1470: 1468: 1467: 1463: 1461: 1460: 1456: 1454: 1451: 1448: 1445: 1443: 1442: 1438: 1436: 1435: 1431: 1428: 1425: 1422: 1418: 1415: 1412: 1409: 1406: 1403: 1400: 1397: 1394: 1391: 1389: 1386: 1384: 1383: 1379: 1376: 1375: 1371: 1370: 1360: 1357: 1354: 1351: 1348: 1345: 1342: 1339: 1336: 1333: 1330: 1327: 1324: 1323: 1319: 1316: 1313: 1310: 1307: 1304: 1301: 1298: 1295: 1292: 1291: 1289: 1285: 1279: 1278: 1274: 1272: 1271: 1267: 1265: 1264: 1260: 1259: 1257: 1255: 1252: 1249: 1245: 1238: 1235: 1233: 1232: 1228: 1227: 1225: 1223: 1219: 1212: 1209: 1207: 1206: 1202: 1200: 1199: 1195: 1194: 1192: 1190: 1186: 1180: 1177: 1174: 1171: 1170: 1168: 1166: 1162: 1155: 1153: 1148: 1147: 1143: 1142: 1140: 1138: 1134: 1127: 1124: 1121: 1120: 1116: 1113: 1110: 1107: 1104: 1103: 1101: 1098: 1094: 1086: 1085: 1081: 1079: 1078: 1074: 1072: 1071: 1067: 1066: 1065: 1064: 1063:Multiuser DOS 1060: 1059: 1057: 1055: 1051: 1044: 1043: 1038: 1037: 1032: 1031: 1027: 1026: 1024: 1022: 1018: 1011: 1008: 1005: 1004: 1000: 999: 997: 995: 991: 980: 977: 974: 971: 970: 968: 964: 956: 953: 950: 947: 945: 942: 941: 940: 937: 935: 934:ITRON project 932: 931: 928: 925: 922: 918: 907: 904: 901: 898: 895: 892: 889: 886: 883: 880: 877: 874: 871: 870: 866: 865: 863: 859: 852: 851: 847: 846: 844: 842: 838: 832: 831: 827: 824: 821: 818: 815: 812: 809: 807: 806: 802: 799: 795: 791: 790: 786: 784: 781: 779: 776: 774: 773: 769: 768: 766: 764: 760: 757: 754: 750: 747: 745: 739: 734: 727: 722: 720: 715: 713: 708: 707: 704: 692: 689: 688: 686: 684:Certification 682: 675: 672: 669: 666: 663: 660: 657: 654: 651: 648: 645: 644:Funk Software 642: 639: 636: 633: 630: 627: 624: 621: 618: 615: 612: 609: 606: 603: 600: 597: 594: 591: 588: 587: 585: 582: 575: 569: 566: 563: 560: 558: 555: 553: 550: 549: 547: 543: 536: 533: 531: 528: 525: 522: 520: 517: 515: 512: 510: 507: 505: 502: 500: 497: 496: 494: 490: 484: 481: 479: 476: 474: 471: 470: 468: 464: 460: 453: 448: 446: 441: 439: 434: 433: 430: 424: 421: 420: 416: 400: 396: 392: 386: 383: 371: 367: 360: 358: 356: 352: 349: 344: 342: 338: 331: 324: 321: 319:1 August 2002 318: 314: 310: 307: 304: 300: 296: 293: 290: 286: 282: 279: 276: 272: 268: 265: 262: 258: 255:24 July 2010 254: 251: 248: 244: 240: 238:19 April 2010 237: 235:19 April 2007 234: 230: 227: 225: 223:23 April 2019 222: 218: 209:Release date 204: 198: 196: 193: 189: 185: 177: 175: 173: 172: 167: 162: 158: 150: 146: 142: 139: 135: 133: 129: 125: 124: 123: 117: 115: 113: 109: 106: 102: 93: 90: 86: 82: 80: 76: 62: 60: 56: 53:Closed source 52: 48: 44: 42:Working state 40: 37: 34: 32: 28: 19: 1790:Novell S-Net 1765:Banyan VINES 1728: 1629: 1619: 1607: 1599: 1594: 1591: 1579:Ken Sakamura 1574:Adam Dunkels 1477: 1471: 1464: 1457: 1452: 1439: 1432: 1380: 1372: 1320: 1287:Low resource 1275: 1268: 1261: 1229: 1203: 1196: 1150: 1149:^° kernel → 1144: 1117: 1082: 1075: 1068: 1061: 1040: 1034: 1028: 1001: 882:Nucleus RTOS 867: 848: 828: 803: 797: 793: 787: 770: 577:Acquisitions 567: 478:Scott Kriens 402:. Retrieved 385: 373:. Retrieved 369: 283:11 May 2009 252:24 July 2009 249:24 July 2006 215:End of life 191: 181: 178:NSA and GCHQ 169: 154: 121: 100: 99: 88:Succeeded by 50:Source model 18: 1775:LAN Manager 1699:Cisco NX-OS 1602:Microkernel 1564:Dave Cutler 1554:Gordon Bell 1459:Sintran III 1329:OpenComRTOS 1030:Chorus/Jazz 676:WANDL ('13) 404:27 December 280:11 May 2008 277:11 May 2005 130:-certified 83:Proprietary 1818:Categories 1709:ExtremeXOS 1621:Comparison 1546:Developers 1507:Frameworks 1449:° Standard 1427:Phantom OS 1405:µ-velOSity 1294:ChibiOS/RT 590:Layer Five 537:SRX Series 534:QFX-Series 526:PTX-Series 523:ACX-Series 375:15 January 332:References 70:2019-04-23 1694:Cisco IOS 1569:Dan Dodge 1497:UniProton 1447:RT-Thread 1421:Microware 1341:RT-Thread 1165:Microsoft 955:T-License 876:Integrity 763:Unix-like 742:Operating 557:Junos SDK 530:EX-Series 519:MX-Series 220:6.3.0r27 161:backdoors 105:real-time 31:Developer 1803:Category 1753:Historic 1729:ScreenOS 1714:Junos OS 1631:Category 1453:ScreenOS 1393:FreeRTOS 1335:PX5 RTOS 1042:ChorusOS 939:T-Kernel 900:PX5 RTOS 869:ChorusOS 778:Junos OS 568:ScreenOS 552:Junos OS 514:E-Series 509:J-Series 504:T-Series 499:M-Series 492:Products 199:Versions 118:Features 101:ScreenOS 92:Junos OS 25:ScreenOS 1785:NetWare 1760:3+Share 1724:pfSense 1719:OpenWrt 1682:Current 1592:Italics 1536:Xenomai 1530:TI-RTOS 1492:VxWorks 1479:Harmony 1382:DioneOS 1353:ThreadX 1322:Nano-RK 1311:FunkOS° 1300:Contiki 1205:4690 OS 1198:4680 OS 1173:ThreadX 1152:Symbian 1084:REAL/32 966:Partial 923:support 896:^ (OSE) 861:Partial 823:RTLinux 798:Unix-RT 755:support 744:systems 140:attacks 79:License 68: ( 45:Current 1780:MS-Net 1374:BeRTOS 1359:Zephyr 1343:° Nano 1315:Mynewt 1277:VAXELN 1263:RSX-11 1251:PDP-11 1126:Wombat 1119:REX OS 1112:PikeOS 1106:LLinux 1099:kernel 1077:FlexOS 1036:JavaOS 850:LiteOS 841:LiteOS 805:OS2000 783:LynxOS 735:(RTOS) 466:People 138:TCP/IP 1744:ZyNOS 1734:SONiC 1676:(NOS) 1473:Thoth 1466:THEOS 1399:µC/OS 1388:embOS 1270:RT-11 1213:(TPF) 1137:Psion 979:RTEMS 888:NuttX 753:POSIX 661:('10) 652:('10) 646:('05) 637:('05) 631:('05) 625:('05) 619:('04) 613:('02) 604:('00) 598:('00) 592:('99) 562:Junos 370:WIRED 171:WIRED 132:IPSec 103:is a 1739:VyOS 1608:° = 1600:^ = 1524:RTAI 1511:kits 1486:VRTX 1476:^ → 1434:pSOS 1417:OS-9 1347:RIOT 1231:DSOS 1146:EKA2 1010:seL4 1003:EROS 973:eCos 921:TRON 906:RIOT 830:UNOS 794:MERT 772:DNIX 581:List 406:2015 377:2016 316:4.0 302:5.0 288:5.1 274:5.2 260:5.3 246:5.4 232:6.0 190:had 188:GCHQ 164:the 128:ICSA 1520:° 2 1441:RMX 1411:MQX 1254:VAX 1248:DEC 1189:IBM 1054:DOS 1033:^ ( 811:QNX 792:^ ( 184:NSA 166:NSA 1820:: 1532:^° 1509:, 1429:^° 1401:^° 1395:^° 1377:^° 1361:^° 1296:^° 1239:^° 1156:^° 1154:OS 1128:^° 1108:^° 1097:L4 1045:^) 1039:+ 1012:^° 1006:^° 908:^° 890:^° 796:– 393:, 368:. 354:^ 340:^ 114:. 1666:e 1659:t 1652:v 1538:° 1526:° 1488:^ 1482:^ 1423:) 1419:( 1413:^ 1407:^ 1355:^ 1349:° 1337:^ 1331:^ 1325:° 1317:° 1308:° 1302:° 1175:^ 1122:^ 1114:^ 981:° 975:° 902:^ 884:^ 878:^ 872:^ 853:° 825:° 819:° 813:^ 800:) 725:e 718:t 711:v 583:) 579:( 564:E 451:e 444:t 437:v 408:. 379:. 72:)

Index

Developer
Juniper Networks
Latest release
License
Junos OS
real-time
embedded operating system
Juniper Networks
ICSA
IPSec
TCP/IP
network segmentation
Juniper Networks
backdoors
NSA
WIRED
NSA
GCHQ


Release Notes 6.3.0r27 Rev 01



"New Discovery Around Juniper Backdoor Raises More Questions About the Company"
Ryan Gallagher
Glenn Greenwald
"NSA Helped British Spies Find Security Holes In Juniper Firewalls"
ScreenOS Software Documentation
v

Text is available under the Creative Commons Attribution-ShareAlike License. Additional terms may apply.