Slashdot Mirror


SSH Backdoor Found In Fortinet Firewalls (arstechnica.com)

An anonymous reader writes: The IT community was shaken a few weeks ago when Juniper Networks firewalls were found to contain "unauthorized code" that seemed to enable a backdoor. Now, Fortinet firewalls have been found to contain an apparent SSH backdoor as well. "According to the exploit code, the undisclosed authentication works on versions 4.3 up to 5.0.7. If correct, the surreptitious access method was active in FortiOS versions current in the 2013 and 2014 time frame and possibly earlier, based on this rough release history. The weakness was eventually patched, but so far, researchers have been unable to locate a security advisory that disclosed the alternative authentication method or the hard-coded password." A spokesperson for Fortinet told El Reg, "This was not a 'backdoor' vulnerability issue but rather a management authentication issue."

3 of 71 comments (clear)

  1. Re:"management" = ??? by phantomfive · · Score: 5, Insightful
    Here is their full quote:

    "This was not a 'backdoor' vulnerability issue but rather a management authentication issue. The issue was identified by our product security team as part of their regular review and testing efforts. After careful analysis and investigation, we were able to verify this issue was not due to any malicious activity by any party, internal or external."

    Their PR firm is earning its money today.

    --
    "First they came for the slanderers and i said nothing."
  2. Re: "management" = ??? by ZeroWaiteState · · Score: 5, Interesting

    The fact that DoD (who is just one government among many) spent well over 9 figures on exploits means that government surveillance actually is the simplest explanation these days.

  3. LOL by JustAnotherOldGuy · · Score: 5, Funny

    A spokesperson for Fortinet told El Reg, "This was not a 'backdoor' vulnerability issue but rather a management authentication issue."

    Later they said, "You didn't get 'pwned', you got 'haxored'...it's like, totally different, man."

    And just for the record, I'm not "eating a potato", I'm "utilizing a starch resource with a multi-pronged utensil!"

    --
    Just cruising through this digital world at 33 1/3 rpm...