Solved

Fed up with Gator....How to block???

Posted on 2004-08-24
8
356 Views
Last Modified: 2010-04-11
I need to block gator at my firewall.  Everyday, I get more and more Snort alerts with Gator and I have had it with chasing down these "infected" systems.

Does anyone have any suggestions.

Thanks,

Craig
0
Comment
Question by:Craig Sharp
8 Comments
 
LVL 49

Expert Comment

by:sunray_2003
ID: 11881228
Craig

check this

http:Q_20442859.html

0
 
LVL 15

Expert Comment

by:Yan_west
ID: 11881363
Get this software:

http://www.javacoolsoftware.com/spywareblaster.html

"Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted pests.
Block spyware/tracking cookies in Internet Explorer and Mozilla/Firefox.
Restrict the actions of potentially dangerous sites in Internet Explorer.

SpywareBlaster can help keep your system spyware-free and secure, without interfering with the "good side" of the web.

And unlike other programs, SpywareBlaster does not have to remain running in the background.
"

It works great, i have it installed and it works perfectly.
0
 
LVL 1

Expert Comment

by:shanepresley
ID: 11885108
It depends what kind of firewall you have.  The best way to block gator at the network/firewall level is with an intelligent firewall or proxy.  Check Point calls this "Application Intelligence" but it's basically just stateful inspection at the application level.  Some other proxies and devices can do it.

To look for gator, look at the HTTP packets for "User-Agent" = "^Gator" and block that.  As I said Check Point FW-1 NG AI can do it.  But so can some other proxies.

Shane
0
 
LVL 3

Author Comment

by:Craig Sharp
ID: 11888229
We have a PIX and it does not have anything close to intelligence.  I am thinking of writing a module for Snort using PERL that will automatically add the rules to the firewall for selected alerts.
0
Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

 
LVL 1

Expert Comment

by:ganan99
ID: 11890198
I would also use Adaware by Lavasoft, to get rid of any spyware you have.
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 11896426
You are correct that the PIX cannot block these connections, but if you have a Cisco router in front of the PIX you would be able to use NBAR (Network Based Application Recognition) to block it..
0
 
LVL 1

Expert Comment

by:HerculesMO
ID: 11958226
You can always edit your HOSTS file to block anything from gator.com or its relatives...

You can google how to add exceptions to c:\windows\system32\drivers\etc\hosts

It's the best bet and your web browser will simply never display anything from Gator, nor will any application.
0
 
LVL 3

Author Comment

by:Craig Sharp
ID: 11958912
Hi all.  Thanks for the replies.  I have accepted lrmoore's response as the NBAR is very close to what I need.  We have a complete Cisco infrastructure and this will be a good fit.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Phishing is at the top of most security top 10 efforts you should be pursuing in 2016 and beyond. If you don't have phishing incorporated into your Security Awareness Program yet, now is the time. Phishers, and the scams they use, are only going to …
This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now