eBay port scans visitors' computers for remote access programs
bleepingcomputer.com
bleepingcomputer.com
I thought about submitting the other article with my own title, but I didn't want to "editorialize".
I think what we might be seeing here is the outcome of some overpaid consultant's claim that they can protect ebay from fraud with 'sophisticated' malware detection.
I'm wondering if eBay displays a fraud warning, or pretends to allow the transaction to occur (shadow bidding?), or just hellbans the account being used.
For shill-bidding farms, the obvious counter is to move remote screen access to non-standard ports, or move to headless browser operation via other scripting methods.
It will just feed the data-point into an anti-fraud/anti-spam system along with everything else.
And the anti-fraud/anti-spam system is probably a machine learning black box. It will learn if this data-point is actually correlated with naughty behaviour, and what other factors are usually correlated.
Bad guys do use compromised seevers and devices,often it's bind() shell (like a webshell) that can easily be detected. I think it helps when they use compromised hosts as proxies to avoid IP restrictions.
Check out some of this guys videos: https://www.youtube.com/channel/UCm22FAXZMw1BaWeFszZxUKw
Feed that into a system that monitors lots of other inputs, and you start to build improved fraud detection systems. Most of these systems benefit significantly from long tail / long history monitoring - all the other providers of systems in this space try to get beacons onto virtually all the pages you visit, monitor all mouse and other movements you carry out etc.
Why not this pretty simple and straightforward explanation vs something complicated about overpaid consultants? Amazon does $80B of sales or something per year. Each 1% of fraud on this platform is worth $800 million. How overpaid must a consultant be who can knock this down?
I'm curious how someone with crypt in their name would ignore obvious remote access trojan installs as a threat vector?
At best, the result of the data points created by this script is going to create a temporary drop in fraud, which can be used by the aforementioned 'consultant' to claim (premature) victory. Give it a month or two, and the fraud numbers are going to go back to their previous levels.
So you'll be wrong here. And even a 6 month decline in fraud is highly valuable to any of these large scale players.
The rest just need to notice they're no longer making money and being 1337, will get updated h4xx0r t00lz once the first group releases them.
Also, the BC article is highly sensationalized coverage with no links to actual source. smh, today's journalists
But why should a user have to subject their machine internals to inspection by eBay? And, without their consent.
IPv6 with a public routed address still means there is a firewall, just like with NATv4. NATv4 just also has a NAT router with that firewall.
Tell that to every corporation on Earth, especially to Banks, that "port scanning your perimeter is an innocent thing". Tell that your employer as well and do tell us what's your job status afterwards.
(I am not downvoting the utterly silly grey comments - I want them to be visible to a) ;)
To what extent do they need consent to port scan, though? They're not intending to do anything malicious, and in fact (assuming you are the owner of the account that's signed in) they're doing it partly to benefit you. Is there a law against port scanning? Does it affect users in any way?
Wait. VNC is a Windows remote access tool? LOL.