eBay port scans visitors' computers for remote access programs

栏目: IT技术 · 发布时间: 3年前

内容简介:When visiting the eBay.com site, a script will run that performs a local port scan of your computer to detect remote support and remote access applications.Many of these ports are related to remote access/remote support tools such as the Windows Remote Des

eBay port scans visitors' computers for remote access programs

When visiting the eBay.com site, a script will run that performs a local port scan of your computer to detect remote support and remote access applications.

Many of these ports are related to remote access/remote support tools such as the Windows Remote Desktop, VNC, TeamViewer, Ammy Admin, and more.

After learning about this, BleepingComputer conducted a test and can confirm that eBay.com is indeed performing a local port scan of 14 different ports when visiting the site.

eBay port scans visitors' computers for remote access programs
eBay.com script performing a port scan

This scan is being conducted by a check.js script [ archived ] on eBay.com that attempts to connect to the following ports:

eBay port scans visitors' computers for remote access programs
Ports being scanned

The fourteen different ports that are scanned and their associated programs and eBay reference string is listed below.

Program Ebay Name Port
Unknown REF 63333
VNC VNC 5900
VNC VNC 5901
VNC VNC 5902
VNC VNC 5903
Remote Desktop Protocol RDP 3389
Aeroadmin ARO 5950
Ammyy Admin AMY 5931
TeamViewer TV0 5939
TeamViewer TV1 6039
TeamViewer TV2 5944
TeamViewer TV2 6040
Anyplace Control APC 5279
AnyDesk ANY 7070

BleepingComputer has not been able to identify the targeted program on port 63333. If you recognize it, please let us know.

The script performs these scans using WebSockets to connect to, which is the local computer, on the specified port.

eBay port scans visitors' computers for remote access programs
Script to use websockets to perform local port scans

According to Nullsweep, who first reported on the port scans, they do not occur when browsing the site with Linux.

Once they tested in Windows, though, the port scans occurred.

This makes sense as the programs being scanned for are all Windows remote access tools.

Likely done to detect hacked computers

As the port scan is only looking for remote access programs, it is most likely being done to check for compromised computers used to make fraudulent eBay purchases.

In 2016, reports were flooding in that people's computers were being taken over through TeamViewer and used to make fraudulent purchases on eBay.

As many eBay users use cookies to automatically login to the site, the attackers were able to remote control the computer and access eBay to make purchases.

It got so bad that one person created a spreadsheet to keep track of all the reported attacks. As you can see, many of them reference eBay.

These port scans are still intrusive and not something that many users would want to happen when visiting a site.

BleepingComputer has contacted eBay about this port scan but has not heard back at this time.

Update 5/25/20: Updated article with correct attribution.

以上所述就是小编给大家介绍的《eBay port scans visitors' computers for remote access programs》,希望对大家有所帮助,如果大家有任何疑问请给我留言,小编会及时回复大家的。在此也非常感谢大家对 码农网 的支持!






方腾飞、魏鹏、程晓明 / 机械工业出版社 / 2015-7-1 / 59.00元

并发编程领域的扛鼎之作,作者是阿里和1号店的资深Java技术专家,对并发编程有非常深入的研究,《Java并发编程的艺术》是他们多年一线开发经验的结晶。本书的部分内容在出版早期发表在Java并发编程网和InfoQ等技术社区,得到了非常高的评价。它选取了Java并发编程中最核心的技术进行讲解,从JDK源码、JVM、CPU等多角度全面剖析和讲解了Java并发编程的框架、工具、原理和方法,对Java并发编......一起来看看 《Java并发编程的艺术》 这本书的介绍吧!


RGB HEX 互转工具

