Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against The WebAttacker Spyware

Subscribe

Check Point Reference: CPAI-2006-083
Date Published:
Severity:
Last Updated:
Source:  Sophos
Industry Reference(s):

 

Protection Provided by: VPN-1
  • NGX R61
  • NGX R60
  • NG with Application Intelligence R55W
  • NG with Application Intelligence R55
  • NG with Application Intelligence R54
VSX
  • NGX
InterSpect
  • NGX
  • 2.0 and 1.x
Who is Vulnerable?
 Microsoft Windows clients
Vulnerability Description
WebAttacker is a spyware kit sold on a Russian website for $15. The kit includes scripts designed to make simpler the task of infecting computers: the buyer spams out a message to email addresses inviting them to visit a compromised website. Once the user enters the compromised website, The website attempts to download the malicious code remotely onto the user's PC by taking advantage of known web browser and operating system vulnerabilities.

Update/Patch Available
 
Vulnerability Details
The Russian website makes the kits available for online purchase and offers technical support to its buyers. 
These kits explain how to lure users into visiting compromised websites. These sites contain JavaScript code that identifies the visiting computer’s browser version and operating system, including any installed patches, and launches the most appropriate exploit. The exploit downloads a program that attempts to turn off the firewall and install malware, generally a password stealer, keylogger or a banking Trojan.

Protection Overview
The Update enables the HTTP Worm Catcher to detect and block the vulnerability based on pre-defined worm signatures. 

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information

The update of July 13 includes the following protections:

WebAttacker Spyware Protection (CPAI-2006-083)
Geeklog Remote Code Execution Protection (CPAI-2006-084)  
Cisco CallManager XSS Protection (CPAI-2006-085)  
Plume CMS Manager Protection (CPAI-2006-086)
ASP.Net Information Disclosure Protection (MS06-033) - CPAI-2006-087
Spyware Installer malware Protection

VPN-1 NGX R61

How Can I Protect My Network?
1. Update SmartDefense: Click the SmartDefense Services tab, click Download Updates and then click the Online Update button.
2. In the Web Intelligence tree, click Malicious Code > General HTTP Worm Catcher.
3. Enable the following pattern:

WebAttacker Spyware

4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: HTTP Worm Catcher
Attack Information: WebAttacker Spyware

VPN-1 NGX R60 & VPN-1 NG with Application Intelligence R55W

How Can I Protect My Network?
1. Update SmartDefense by clicking Online Update in the SmartDashboard General window.
2. In the Web Intelligence tree, click Malicious Code > General HTTP Worm Catcher.
3. Enable the following pattern:

WebAttacker Spyware

4. Install policy on all modules.
 

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: HTTP Worm Catcher
Attack Information: WebAttacker Spyware

VPN-1 NG with Application Intelligence R55/R54

How Can I Protect My Network?
1. Update SmartDefense by clicking Update Now in the SmartDashboard General window.
2. In the SmartDefense tree, click Application Intelligence > Web and enable General HTTP Worm Catcher.
3. Enable the following pattern:

WebAttacker Spyware

4. Install security policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: HTTP Worm Catcher
Attack Information: WebAttacker Spyware

VPN-1 VSX NGX

How Can I Protect My Network?
1. Update SmartDefense by clicking Online Update in the SmartDashboard General window.
2. In the Web Intelligence tree, click Malicious Code > General HTTP Worm Catcher.
3. Enable the following pattern:

WebAttacker Spyware

4. Install policy on all modules. 

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: HTTP Worm Catcher
Attack Information: WebAttacker Spyware 


 

InterSpect NGX

How Can I Protect My Network?
1. Update SmartDefense: In the left pane from the drop-down list, select Profiles > SmartDefense Service and click the Online Update button.
2. In the left pane, select Profiles > Default Protection and select the Web Intelligence page of the profile.
3. In the Web Intelligence tree, click Malicious Code > General HTTP Worm Catcher.
4. Enable the following pattern:

WebAttacker Spyware

5. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: HTTP Worm Catcher
Attack Information: WebAttacker Spyware

InterSpect 2.0

How Can I Protect My Network?
1. Update SmartDefense by clicking Online Update in the SmartDashboard General window.
2. In the SmartDefense tree, click Web > General HTTP Worm Defender.
3. Enable the following pattern:

WebAttacker Spyware

4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: HTTP Worm Catcher
Attack Information: WebAttacker Spyware