Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

How To Protect Against Instant Messaging Vulnerabilities: Blocking Google Talk

Subscribe

Check Point Reference: SBP-2006-02
Date Published:
Severity:
Last Updated:
Source: SmartDefense Research Center
Industry Reference(s): CVE-2005-3899
CVE-2005-3678
Protection Provided by: VPN-1
  • NGX R61
  • NGX R60
  • NG with Application Intelligence R55W
InterSpect
  • NGX
Who is Vulnerable?
Microsoft Windows operating systems
Vulnerability Description
Google Talk is an application used to call or send instant messages for Microsoft Windows operating systems. Instant messaging applications may risk an organization's security in the following ways:

1. Vulnerabilities in IM applications could be exploited to compromise a user's system (i.e MSN Messenger PNG image processing).  
2. An important capability of IM is file transfer that could be exploited by worms to infect a user's system.
3. Using voice data along with file transfers may result in excessive bandwidth utilization.

SmartDefense allows you to block Google Talk on standard and non-standard ports as well as to block its Web interface.

Vulnerability Details
SmartDefense allows you to block Google Talk in the following ways:

1. Blocking Google Talk on its default ports 5222/tcp and 5223/tcp.
2. Blocking Google Talk connections generated by non-Google Talk clients on ports SSL/443 and HTTP/8080.
3. Blocking Google Talk via the Web version of Google Talk. This interface allows a user to use Google Talk without installing the IM client on his system.

Protection Overview
Check Point has provided several Google Talk protections:

Blocking Google Talk via Gmail Web interface (Update from Match 20, 2006)
Similarly to other instant messaging applications, Google has added a Web version of Google Talk whereby a user does not need to install the IM client on his system. The update enables to block Google Talk via the Gmail Web interface based on a specific Worm Catcher pattern. This update applies to VPN-1 NGX R61 and InterSpect NGX.

Blocking Google Talk connections from non-Google Talk clients (Update from January 24, 2006)
The update enables you to block Google Talk connections coming from non-Google Talk clients. This inspection is performed on ports 5223, SSL/443 and HTTP/8080.

Blocking Google Talk traffic over default Google Talk ports: Update from November 30, 2005 (CPAI-2005-151)
The Update identifies the Google Talk protocol and blocks Google Talk traffic on its default ports 5222/tcp and 5223/tcp.

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information
SANS Top Internet Security Vulnerabilities

VPN-1 NGX R61 & InterSpect NGX

How Can I Protect My Network?
1. On the SmartDefense navigation tree, click Application Intelligence > Instant Messengers and enable Google Talk.
2. Install policy on all modules.

To activate the Google Talk via Gmail Web interface protection:
1. In the Web Intelligence tree, click Malicious Code > General HTTP Worm Catcher.
2. Enable the following pattern:

Google Talk via Gmail Interface

3. Install policy on all modules.

How Do I Know if My Network is Under Attack?

When activating the Google Talk protection SmartView will log the following entries in case of an attack:

Attack Name: Instant Messengers
Attack information:
Google Talk detected on connection
Google Talk masquerading as SSL detected on connection
Google Talk has encountered an internal error. This may be caused by a corrupt packet or internal limits exceeded

When activating the Google Talk via Gmail Web Interface, SmartView Tracker will log the following entries in case of an attack:

Attack Name: HTTP Worm Catcher
Attack Information: Google Talk via Gmail Web Interface

VPN-1 NGX R60 & VPN-1 NG with Application Intelligence R55W

How Can I Protect My Network?
1. On the SmartDefense navigation tree, click Application Intelligence > Instant Messengers and enable Google Talk.
2. Install policy on all modules.

How Do I Know if My Network is Under Attack?
When activating the Google Talk protection SmartView will log the following entries in case of an attack:

Attack Name: Instant Messengers
Attack information:
Google Talk detected on connection
Google Talk masquerading as SSL detected on connection
Google Talk has encountered an internal error. This may be caused by a corrupt packet or internal limits exceeded