Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Trojan/Spy. Goldun.de Vulnerability

Subscribe

Check Point Reference: CPAI-2006-025
Date Published:
Severity:
Last Updated:
Source: Check Point Virus Information Center
Protection Provided by: VPN-1
  • NGX R61
  • NGX R60
  • NG with Application Intelligence R55W
  • NG with Application Intelligence R55
  • NG with Application Intelligence R54
InterSpect
  • NGX
  • 2.0 and 1.x
Who is Vulnerable?
Windows 95
Windows 98
Windows 98 SE
Windows NT
Windows ME
Windows 2000
Windows XP
Windows 2003
Vulnerability Description
Goldun.de.1 is a trojan for the Windows platforms. The trojan drops malicious files, modifies system Registry, steals information and may also assume remote control over an affected machine.
Vulnerability Details
Goldun.de.1 also downloads and executes files from a remote server. The trojan Installs through exploits and can also be downloaded by other malwares.

Protection Overview
The update blocks the vulnerability based on a unique HTTP header pattern.

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information
The update also includes the following protections:

  • Enhancement to the Microsoft Windows Media Player Vulnerability (CPAI-2006-016)
  • ezDatabase Remote File Inclusion Protection (CPAI-2006-026)
  • TFTPD32 Request Error Message Format String Protection (CPAI-2006-027) - InterSpect NGX only
  • Cisco IOS CDP Status Page Code Injection Protection (CPAI-2006-028)
  • SHOUTcast Filename Request Format String Protection (CPAI-2006-029)
  • Oracle Report File Overwrite/Oracle Report Directory Traversal Protection (CPAI-2006-030)
  • Google Talk via Gmail Web Interface Protection (CPSA-2006-02)
  • IBM Tivoli Access Manager Directory Traversal Protection (CPAI-2006-031)
  • Protection Against NFS Vulnerabilities (CPAI-2006-032)
  • Protection against PmWiki multiple vulnerabilities.

VPN-1 NGX R61

How Can I Protect My Network?
1. Update you SmartDefense: Click the SmartDefense Services tab, In the left pane from the drop-down list, click Download Updates and then click the Online Update button.
2.  On the Web Intelligence tree, click HTTP Protocol Inspection > Header Rejection and enable the following pattern:

Trojan Spy Goldun.de

3. Install policy on all modules. 

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Header Rejection
Attack Information: Trojan Spy Goldun.de

VPN-1 NGX R60 / VPN-1 NG with Application Intelligence R55W

How Can I Protect My Network?
1. Update your SmartDefense by clicking Online Update in the SmartDashboard General window.
2. On the Web Intelligence tree, click HTTP Protocol Inspection > Header Rejection and enable the following pattern:

Trojan Spy Goldun.de

3. Install policy on all modules. 

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Header Rejection
Attack Information: Trojan Spy Goldun.de

VPN-1 NG with Application Intelligence R54/R55

How Can I Protect My Network?
1. Update your SmartDefense by clicking Update Now in the SmartDashboard General window.
2. In the SmartDefense tree, click Application Intelligence > Web > Peer to Peer.
3. In the Header Detection table, enable the Trojan Spy Goldun.de pattern.  
4. Install security policy on all modules.

 

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Header Rejection
Attack Information: Trojan Spy Goldun.de

InterSpect NGX

How Can I Protect My Network?
1. Update your SmartDefense: In the left pane from the drop-down list, select Profiles > SmartDefense Service and click the Online Update button.
2. In the left pane, select Profiles > Default Protection and select the Web Intelligence page of the profile.  
3. In the Web Intelligence tree, click HTTP Protocol Inspection > Header Rejection and enable the following pattern:

Trojan spy Goldun.de

4. Install security policy on all modules. 

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Header Rejection
Attack Information: Trojan spy Goldun.de

InterSpect 2.0

How Can I Protect My Network?
1. Update your SmartDefense by clicking Online Update in the SmartDashboard General window.
2. In the SmartDefense tree, click Application Intelligence > Web > Peer to Peer.
3. In the Headers Detection table, enable the following pattern:

Trojan Spy Goldun.de

4. Install policy on all modules.

 

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Header Rejection
Attack Information: Trojan Spy Goldun.de