eBay is port scanning visitors to their website
blog.nem.ec
blog.nem.ec
or look into the following filesystem path in Linux: /sys/firmware/acpi/tables
Edit: @Windows users: pip install pydivert and then try to write a script to block connections from Chrome to non-Chrome processes. you might need GetTcpTable2() or something. (Looking into this now. Check out http://stackoverflow.com/a/25431340)
One thing that could break due to this could login via XYZ network which opens a new tab in the default browser for authentication.
[0] https://addons.mozilla.org/en-US/firefox/addon/happy-bonobo-...
network.websocket.max-connections=0
This is a global setting and is applied to all websites. I also wasn't able to test this myself yet. Are there any good extensions for blocking websockets on for specific domains?[0] https://nullsweep.com/why-is-this-website-port-scanning-me/
If IT admins get wind of this they'll just block it (or never unblock it since it's been blocked by some from day 1) and our product gets degraded experience.
Fits right there with unnecessary password rules too.
Ebay will have your IP from your request so they can run nmap against your machine from their server without your browser ever knowing about it.
I also know of a bank that does similar via an old school sort of way, their online banking login page tries to load images from urls made up of your IP and various ports.
Presumably these are targeting known ports for online banking malware C&C http traffic rather than remote desktop services though.
And this is a bank that still uses frames 'for security', so it must be an old technique!
They could still portscan from afar and it would still be sketchy, but using Websockets makes it worse
(Or at least, that was what someone else claimed last time this came up on HN)
There's a blocklist that may make it into uBO in the future that blocks 3rd party access to localhost and other IANA reserved IP addresses, though.
https://github.com/uBlockOrigin/uBlock-issues/issues?q=is%3A...
But seriously, many new specs are very obviously abusable, yet on HN people seem unwilling to accept "this feature is trivially abusable" as a reason to not give developers a new feature, even when it is user hostile.
Web specs, and the webdevs he frequently want them, need to consider abusive developers being the default users of the API.
When working on WebGL it took an absurd amount of work to get non-web folk to understand that the spec had to be very tight and verifiable. I literally had to deal with people arguing that "developers won't ship shaders that crash the machine". It was painful.
Aside from being intensely maligned and full of security holes, it doesn't (or didn't?) support WebRTC.
So being called IE is sarcastic like ha ha if you're so concerned about security downgrade to IE which doesn't support WebRTC.
The implication being in this case that people were calling Safari too "conservative", so to speak.
$websocket
to override this for sites which break use e.g.
@@gateway.discord.gg$websocket
I've heard with uMatrix you can block all sites from trying to access localhost/127.0.0.1, which should stop the fingerprinting in its tracks. You may need to enable on a few sites that use localhost for legit things, but those aren't super common.
https://github.com/uBlockOrigin/uBlock-issues/issues?q=is%3A...
Similar to how you can make it prompt to store Cookies, provide Location, use the Camera/Mic, etc.
Many companies or persons share their desktops for remote usage. Later they sell this service to eBay users. And they're using it for different fraudulent activities - from making real sales (just for stars) to bidding to own items (for rising price).
For years eBay fight this.
And even if they decided don't they have any responsibility to tell the users.
It is not just for a corporation to suddenly decide the law is unfair when they are subjected to it when real people have been harmed by the same law.
He's saying people let others use their eBay accounts through RDC to game the system.
Also it's an auction site. People want to raise the price by bidding on their own items
So let's we have fraudseller_1 that sell something like iPhone. Here comes honestbuyer_1 that bid for this item with $50. Seller sees offer, but want to rise it.
Since seller can't use his own IP he is using some remote desktop to login somewhere else as fraudbuyer_1 (different account!) and bid $100. Then he wait honestbuyer_1 to bid again. If this happens then two - fraudbuyer_1 and honestbuyer_1 can "race" (note the quotes!) for this item.
Of course this is simplified scenario because can be involved pack of fraud buyers to fool buyers.
I know some person IRL that was involved 10 years ago in such activities. So his friend sells vacation homes and buyers from UK bidding for them. But if seller doesn't like bids he call to that person to make bid from his own account. And of course to rise price with least $1000.
But... this can't be track using eBay since it's via phone call and no remote sessions. Today sellers using virtual desktops (RDP, VNC, TeamViewer or other) to do this.
Seller B is having a hard time making sales. She thinks he needs better ratings. So she logs into the site using a remote client and 'buys' 10 of her items on different accounts and leaves 10 glowing reviews.
Ebay is scanning ports to detect the tools used to do this.
So why don't you set the starting price at $10? Does ebay not let you set the base price?
It's the same thing with the penny auction sites like DealDash which is part of their terribleness.
Either the consumer or the merchant bears the cost for fraud, rarely does paypal or the banks if they did the problem of identity fraud would be solved, and would not be called "identity theft"
Is this really a thing? I thought everybody just used residential proxy/VPN services like luminati. It makes sense too, because a proxy service is way easier to adapt to your application than a remote desktop service.
https://www.bleepingcomputer.com/news/security/list-of-well-...
Here's the discussion about it:
If you’re worried about privacy, use CCPA’s right to information and ask them for a dump of everything they have on you. They are supposed to give you info that other SPs like Threatmetrix have on you as well if they really are transmitting it to 3rd parties.
This isn't a privacy protection, though, but a measure for accountability. That is, only the absence of data aggregation would still someone's worry about privacy.
That doesn't mean they should be allowed to behave like cybercriminals. The risk of fraud doesn't give them a free pass to abuse our trust and invade our privacy. They aren't entitled to know what software people run on their own computers. Especially if they learn this information through underhanded means like port scanning people's local networks without their permission or knowledge. It doesn't matter how much money they're losing because of fraud, they don't get to violate these boundaries in order to reduce the risk associated with their own business.
Are there cops who misuse their power? Absolutely. Are there spies who use information for personal gains? Sure. There need to be checks and balances that make it bad for such people to go rogue.
Privacy acts aim to do some of that. They bring accountability but also an ability to opt out (the latter is hard though - akin to ostracizing oneself from a community).
The real problem is the audacity of these people. They think they can do whatever they want. Not only that, they think they are justified in doing it. They need this information for their own purposes, so they just take it from people without asking, without even informing them. In their minds, what they did was not objectionable. They needed to do it, so they didn't do anything wrong. Those fraudsters left them no choice: they just had to invade the privacy of every single person who visited their website.
It's the same logic every abuser uses. It betrays a fundamental lack of respect for the people who use their service. It's impossible to have trust without this respect.
If they try to infer the active port numbers on your computer to see if there’s a Remote Desktop installed by a bot, you’re not okay.
What’s the alternative? Do you want them to disclose everything they do in a marketing article even though 99.99% of people will have no clue what that means and 10 of the 100 people that bother to read and understand will use it against them. To what end? To gain your trust? You - who has already given them your credit card number, mothers maiden name and city where you first got intimate with your first partner?
index.html:
<html>
<head></head>
<body>
<div id="message"></div>
<script>
let ws = new WebSocket("ws://localhost:5000/");
ws.onopen = () => ws.send("hello server!");
ws.onmessage = ev => {
const $message = document.getElementById("message");
$message.textContent = `ws://localhost:5000/ response: ${ev.data}`;
};
</script>
</body>
</html>
server.js: const express = require("express");
const http = require("http");
const WebSocket = require("ws");
const app = express();
const server = http.createServer(app);
const wss = new WebSocket.Server({ server });
wss.on("connection", ws => {
ws.on("message", message => {
console.log(`received: ${message}`);
ws.send("hello client");
});
});
server.listen(5000, () => console.log("ws server listening on localhost:5000"));
Server runs on localhost:5000. Now serve index.html from any other origin and see it talk to the server without any problem.Browsers set the "Origin" header for ws:// calls, and the websocket servers are expected to check that. Without the check, it'd be possible to issue blind writes (CSRF) from random webpages to the ws:// endpoints. If you're using main site authentication with a separate websocket domain and auth'd requests, all garden variety security scanners will flag the separate websocket domain as a problem, and only the robust ones actually try to validate the server side configuration.
Disclosure: I have triaged and responded to a few of such reports.
> Browsers set the "Origin" header for ws:// calls, and the websocket servers are expected to check that.
I know that, but as always insecure by default protocols are terrible, and are guaranteed to be exploited beyond recognition... The question is why not be secure by default and force servers to whitelist origins they expect to talk to?
That's probably because websockets require asynchronous servers optimizing for number of active connections, while normal sites are best served by servers optimized for response time.
Of course, you can have both handled by the same origin, but it's not the blatantly obvious way.
I thought it was only public ip ports.
In addition, I would expect such a DB to go stale very quickly.
[0] https://zmap.io/
That’s illegal in most circumstances (at least in the US).
At the end of the day, we all need to realize that we send out far more information than we receive when we surf the web.
1. Local Overrides feature allows you to persist and edit source files across page loads (unfortunately only source files currently, so you're out of luck if the JS comes from an XHR or something)
2. F3 on the network panel will let you search for a string across all resources the page loaded. Can be useful for tracking down where stuff like user-agent checks are called (if not obfuscated).
Also calling the code obfuscated is pretty generous. It's amazing how common things like shift ciphers, XOR tricks, etc. are when the browser's REPL cuts through them like butter.
However, I encourage you to be careful and only block web browsers to localhost using this method, because lots of macOS applications depend on localhost connections to talk to themselves, so if you block everything from talking to localhost you may break e.g. LittleSnitch, macOS itself, etc. NO WARRANTY, HAVE BACKUPS, standard stuff.
To set this up, for each /Applications/Browser.app, create a LittleSnitch 'Deny Connections' To 'IP Addresses' rule and enter '127.0.0.1, ::1' without quotes into the text field and click OK. Then right-click on the newly-created application rule and select 'Increase Priority', which will bold the rule text 'Deny outgoing connections to 2 IP addresses'. Repeat this for each Browser.app you use.
If you'd like to specifically enable certain localhost ports to be accessible by your browser (such as 80/443), you can create another rule using the above steps, but before saving the rule, change 'Deny' to 'Allow' and click the '\/' dropdown caret button and enter the appropriate port and select TCP. I encountered some UI quirks doing this but once it's created it works as it should.
Here's a screenshot of the results of my testing for comparing against. I'm not really familiar with how LS works so I can't offer much support, but I fresh-installed it and left all the defaults alone and it worked, so more advanced users shouldn't have much trouble. https://i.imgur.com/T0yqrdM.png
Good luck!
(For those wondering if other software can do this, I tested various macOS application firewalls today and most of them either global-allow localhost connections or don't offer outbound filtering at all. So far, the only one that can block web browsers only from connecting to localhost is LittleSnitch, with some quirks that I wrote a note to their support about. At least one let me create the rule and cheerfully said it was active and then it didn't block anything.)
Standard clearly states that pretty much nothing: https://www.w3.org/TR/websockets/#concept-websocket-close-fa...
Sure they're shady and that needs to be blocked, but security implications? Pretty much nil.
Fingerprinting. Vulnerability discovery. Messing up programs that don't know how to deal with unexpected HTTP requests.
For some reason, I remember one company router kept making http request on port 5000 or 8000, can't remember which port, because it was literally showing on the terminal, with the http path, at random times.
I'm sure being a hacker must be pretty fun these days.
This feels more effective and less intrusive. Not sure why ebay went this rather weird and creepy way instead.
They may not even be using it actively yet because they'd need to gather a lot of example data to detect outliers.
Edit: But, thefreeman above just informed me there's actual new information in this article (which I originally hadn't read, because the comments here made me assume it was the same as the last story on HN). So, thanks!
It's an opinion, I suppose, but it doesn't seem to be based on reasonable expectations. Anyone can portscan anyone else, lots of security researchers have published their findings from portscanning large IP address ranges etc. ... If I don't want other people to see or access open ports on my system, I can firewall them.