Attackers are hunting for tampered Juniper firewalls

A 'honeypot' mimicking a Juniper firewall is seeing login attempts

An experiment by a cybersecurity research center shows attackers are trying to find Juniper firewalls that haven't been patched to remove unauthorized spying code.

The SANS Internet Storm Center set up a honeypot -- a term for a computer designed to lure attackers in order to study their techniques -- that mimicked a vulnerable Juniper firewall.

The honeypot was configured so that it appeared to run ScreenOS, the operating system of the affected Juniper firewalls, wrote Johannes Ullrich, CTO of the Internet Storm Center, on Monday in a blog post.

Juniper said last Thursday that it found during an internal audit two instances of unauthorized code in some versions of ScreenOS, which runs its NetScreen model of enterprise firewalls.

One problem was a hard-coded password, which could allow an attacker to log into a firewall using SSH or telnet in combination with a valid username.

The password was published on Sunday by the security firm Rapid7, which had been analyzing ScreenOS.

Juniper released patches for the password issue and another problem, which could allow VPN traffic to be monitored and decrypted.

Administrators were advised to patch immediately, and Juniper's revelation has received wide attention in the security community. But that still doesn't mean every company has patched, which puts them at risk.

Attackers often quickly try to take advantage of security vulnerabilities after patches are issued in hope of catching out organizations that are slow to react.

Ullrich wrote that the honeypot saw "numerous" login attempts over SSH using the hard-coded password. The attackers also tried various usernames, such as "root," "admin" and "netscreen."

"Our honeypot doesn't emulate ScreenOS beyond the login banner, so we do not know what the attackers are up to, but some of the attacks appear to be 'manual' in that we do see the attacker trying different commands," Ullrich wrote.

One of the IP addresses listed as the source for some of probes was flagged as belonging to the network security company Qualys, possibly attempting to estimate how many systems remain unpatched.

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest News Articles


GGG Evaluation Team

Kathy Cassidy


First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni


For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell


The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi


The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Simon Harriott


My first impression after unboxing the Q702 is that it is a nice looking unit. Styling is somewhat minimalist but very effective. The tablet part, once detached, has a nice weight, and no buttons or switches are located in awkward or intrusive positions.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?