Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

GoToMyPC Protection

Attack ID: CPAI-2005-131
Publish Date:
Category: Remote Control Applications
Vulnerable Systems: Microsoft Windows operating systems
Source: SmartDefense Research Center
Description:

GoToMyPC is a Web-based application which enables SSL browser-based access to a Windows computer through the GoToMyPC Web site. GoToMyPC allows use of a standard Web browser to remotely control a computer over the Internet. This includes full control over all files and network resources present on the remote computer. While the GoToMyPC application can be used to provide legitimate access to corporate resources, the program can also be used by attackers to access unauthorized computers even if these were behind a firewall.

Severity:
Details:

GoToMyPC can be used to bypass the corportae firewall and breach security. For more information about GoToMyPC, refer to Computer Associates Spyware Information Center.

Attack Detection: Users of VPN-1 NGX R60 who have applied the solution outlined below will identify the following log entries:

Attack Name: SSL Enforcement - GoToMyPC Detected
Attack Information: GoToMyPC connection attempt detected
Solution:

Users of VPN-1 NGX R60 should update their SmartDefense by clicking the Update Now button on the SmartDefense General window.

The protection detects and blocks GoToMyPC connection attempts made both on the application's well-known port (8200/TCP) and on other ports. GoToMyPC produces a large number of connections which may result in excessive number of logs. A log suppression mechanism is being used so that a log will be output every 5 minutes per IP.

To enable the GoToMyPC protection:

1. On the SmartDefense navigation tree, click Application Intelligence > Remote Control Applications and enable GToMyPC.

2. Install security policy on all modules.

 

Industry Reference:
Additional Information: This Update also includes:
- protection against malformed AVI files (CPAI-2005-129)
- an option to block Check Point Visitor Mode, traversing the VPN-1 or InterSpect module.