News: 1590496754

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

eBay users spot the online auction house port-scanning their PCs. Um... is that OK?

(2020/05/26)


Updated Users visiting eBay have spotted that the website runs port scans against their computer, using the localhost address to inspect what may be running on your machine.

Fraud is a big issue for eBay, and if the purpose of scanning for remote-control access ports is an attempt to detect criminals logged into a user's computer in order to impersonate them on the tat bazaar, it could have some value. The behaviour, however, was described as "clearly malicious" [1]by security researcher Charles Belmer .

The script attempts WebSocket connections to a number of ports, including 3389 (Microsoft remote desktop), 5931 (Ammy Admin remote desktop), 6333 (VNC remote connection), 7070 (realAudio and Apple QuickTime streaming) and more. The script is running locally so it is not testing for ports exposed to the internet, but rather for what is running on your local network. The port scanning script does not always run. We have only seen it run on Windows, and normally only on the first visit to eBay after some unspecified period.

[2]

The script used by eBay, or its partner LexisNexis, to scan ports on your computer (click to enlarge)

Developer Dan Nemec [3]used browser debugging tools to trace what is going on – a job made harder, he said, by JavaScript code that is "re-obfuscated on every page load" so that variables names change every time.

It is odd, though: not all the code is obfuscated, so if the script's creators really wanted to cover their tracks they could have done a better job.

Nemec did discover several points of interest, however. One is that the source of the script, called check.js, is src.ebay-us.com, which is a CNAME record pointing at h-ebay.online-metrix.net, which belongs to an organisation called ThreatMetrix Inc, part of LexisNexis Risk Solutions.

[4]

Following the trail ... The script is served by online-metrix.net, which is owned by ThreatMetrix, according to tools at [5]MXToolbox

Following the scan, Nemec observed, the web page requests images, again from the Threat Metrix domain, which return a 204 code meaning "no content". The payload is in the argument accompanying the requests, which when decrypted contains the results of the port scan and other information, including the user agent (browser identifier), public IP address, and "other data, signatures and things I don't recognize," said Nemec.

LexisNexis Risk Solutions provides "powerful linking technology... to manage risk and find opportunities," according to its home page, and promises to help companies "walking the tightrope between fraud and friction", as they try to give the customer a smooth online experience while also minimising fraud.

In a [6]white paper the company talks about how to "gather ample 'trust data' around customers and their linked devices" for which it uses techniques including "device fingerprinting and linking across devices". This may not refer specifically to the technology in the eBay script, but it is obvious that the company is in the business of gathering data for both fraud prevention and digital marketing.

Bank on it: It's either legal to port-scan someone without consent or it's not, fumes researcher [7]READ MORE

There is no suggestion that eBay is trying to make use of services like VNC to connect to your computer. While it is likely eBay is using the practice to detect fraud, there are a number of issues concerning privacy, consent and security. The Register has [8]come across ThreatMetrix before , when Halifax bank was found to be conducting port scans, with some claiming that the practice was in breach of the UK's [9]Computer Misuse Act . The bank retorted that it was perfectly legal and argued that the port scans helped it to pick up evidence of malware infections on customers' systems.

The EU's General Data Protection Regulation (GDPR) - [10]already transposed into law in the UK - is another relevant piece of legislation, setting out the conditions for when gathering personal data is lawful and giving individuals rights to obtain and erase personal data in most circumstances.

There is also the question of under what circumstances web browsers should allow requests to services running on localhost. A year ago, the Zoom web-conferencing software was found to using a request to a local web server to open its application from a web page, with the [11]result that "a malicious attacker is able to forcibly join anyone with the vulnerable software installed into a video call with their camera active by default".

We have asked both eBay and LexisNexis for comment. ®

Updated to add

eBay got back to us to say that it is "committed to creating an experience on our sites and services that is safe, secure and trustworthy," though it has not responded to any specific concerns over privacy or security. We understand that the reason for the port scanning script is fraud prevention, seemingly by flagging up machines that may be under remote control by miscreants.



[1] https://nullsweep.com/why-is-this-website-port-scanning-me/

[2] https://regmedia.co.uk/2020/05/26/scanning2.png

[3] https://blog.nem.ec/2020/05/24/ebay-port-scanning/

[4] https://regmedia.co.uk/2020/05/26/threatmetrix.png

[5] https://mxtoolbox.com/SuperTool.aspx?action=a%3asrc.ebay-us.com&run=toolpage

[6] https://risk.lexisnexis.com/insights-resources/white-paper/fraud-in-communications-media-and-mobile-part-4

[7] https://www.theregister.co.uk/2018/08/07/halifax_bank_ports_scans/

[8] https://www.theregister.co.uk/2018/08/07/halifax_bank_ports_scans/

[9] https://www.legislation.gov.uk/ukpga/1990/18/contents

[10] https://www.theregister.co.uk/2020/02/20/google_shifting_uk_data_to_us/

[11] https://bugs.chromium.org/p/chromium/issues/detail?id=951540

This is not okay

IneptAdept

There is no explicit request to allow this request, so the domain has now been completely blocked at all levels

Router

Firewall

Devices

Not that I use eBay much nowadays

Re: This is not okay

Shadow Systems

Just added them to my Hosts file & will be rebooting in a moment to make it stick.

You port scan my computer, I blackhole your fekkin' arse.

Re: This is not okay

Anonymous Coward

If you're using Windows its already persistent. Takes effect from the moment you save the file back. Usually just after you've tried the first time and realised that Notepad isnt UAC aware......

Re: This is not okay

Pascal Monett

Absolutely. You want to scan my computer ? You pop up the question and ask me, along with a description of what you are looking for, where you're looking for it and why you think you have the cheek to ask me.

If you do security checks on your side of the intertubes, that's your business and nothing I have the right to wail about, but on my side, you will only do what I bloody well allow you to.

Re: This is not okay

Anonymous Coward

meanwhile, 99.999999% of users: domain... scanning... ports... click

:(

Isn't this the same company that has users download DLL-files?

Drew Scriver

Correct me if I'm wrong, but doesn't eBay still use ".dll"-extensions? A number of proxy servers block that by default as part of the stronger security sets - and for very good reason.

Seems they want to load a scandal (or more) on mine

Efer Brick

https://www.ebay.com/scl/js/ScandalLoader.js

(blocked, natch)

Chris G

UBlock Origin on Firefox will block eBay's shenanigans, there are other alternatives.

A friend used ThreatMetrix at a company where he worked

Anonymous Coward

They build a complete history of email addresses, phone numbers, etc. entered on their customers sites, their JS also creates a machine fingerprint. IIRC there're some 400+ data data points used to score the client. TM can tell you when the email address was first seen by one of their customers, if it's a catch-all, or disposable, etc. The number of account registrations on customer sites in the last x days, etc, etc. From that they build a credibility score based on the weighting you give to any of the parameters. I remember him saying that his firm refused to send a lot of the available/requested data items on privacy grounds.

If you shop online, there's a high probability you're already in their system along with who knows what PII

Puzzled

Martin

If I have no incoming ports open on my firewall (and surely that's the default for most people on a normal NAT router) then what can they do? I'm not saying I approve of eBay trying to do anything on my computers, but surely most people these days (whether malicious or not) will be behind a standard NATting router in it's default state. So I don't see what eBay are gaining from this.

Or am I completely misunderstanding what they are doing?

---> nearest we have to a "?" icon.

Re: Puzzled

Anonymous Coward

The scans are being conducted by them via their 'secure' page, if effectively has an encrypted link through your firewall as it's using the encrypted traffic to your browser.

Re: Puzzled

AMBxx

The Javascript that's doing the scan is running locally so your router's ports aren't involved outside those used to deliver the web page.

I'm sure the array of add-ons I have in Firefox would block the attempt, but as they also block the login page, I'm forced to use Chrome for ebay.

Re: Puzzled

Anonymous Coward

I can only think that it's part of the fingerprinting. If they scan 200 ports, whether open or closed, then that's another 200 bits of entropy they have mined from you.

My firewall - getting updated

alain williams

iptables -A INPUT -i lo -s 127.0.0.0/8 -d 127.0.0.0/8 -j ACCEPT

It seems that I was naive, I now only allow some connections. Its going to be a pain until I get the rules right.

Could they do a better job?

Mike 137

"not all the code is obfuscated, so if the script's creators really wanted to cover their tracks they could have done a better job."

Maybe they're blindly using an obfuscation tool they don't really understand.

Downright illegal

oiseau

Hello:

... obvious that the company is in the business of gathering data ...

Indeed ...

What they use the data they gather is anyone's guess* but you can be certain that it is not just a fraud prevention exercise.

And if we take into account that what they are doing is very shady if not downright illegal ...

O.

* not really, it's either up for sale or payment on behalf of eBay for the "service" rendered.

whitepines

And what do you think Ebay's response to you actively scanning their servers, perhaps behind their firewalls via exploits, "to protect against fraud" would be? After all, just because it says ebay.com in the browser doesn't mean their site is secure or that you are on the legitimate ebay.com.

I suspect the response would be in terse legalese threatening hacking charges and prison. It's the active penetration / behind firewalls part of what Ebay is doing that probably makes it illegal, but IANAL.

Fraud is a big issue for etailer

macjules

Probably because they got so good at making sure users can be defrauded. I stopped using eBay many years ago when the steps you needed to take to prevent AFF criminals outweighed the value of the goods you were selling.

Once memorably got a $500 transaction on eBay cancelled and refunded when the seller assured my wife that the bag she had bought was "genuene aligator [sic]" I informed eBay that if they did not cancel and refund that I would have them charged under CITES.

Anonymous Coward

Why do browsers have port scanning capabilities via JavaScript?

eBay got back to us to say that

Anonymous Coward

the reply bots they employ didn't read your questions and / or didn't understand them and / or don't give a flying monkey fuck because they're not paid to provide any meaningful answers, so they chose a random reply No 36366 thank you & good bye.

Or, should I read they did provide a meaningful answer to a (presumably) clear question, only that I'm too simple to see the true meaning in their reply?

Fraud is a big issue yada yada...

2+2=5

Presumably a lot of eBay fraud is fraudsters buying an 'eBay fraud kit' on the dark web which provides handy features for defrauding buyers and or sellers. So I fully expect that an updated version of that kit was released about 5 minutes after eBay first started doing these scans.

As always, it's us that suffers - the fraudsters won't be impacted in the slightest, except a one-off upgrade payment for the updated fraud kit.

TRUST is a two way street

redpawn

I don't run Windows except when a special application is needed for both TRUST and speed issues. uBlock Origin on Linux makes me feel a bit better. However, lack of transparency does not lend me to volunteer any info to eBay. I would ditch eBay but parts can be hard to come by through other channels without paying too much for both shipping and the part here in Hawaii. Keeping old kit running keeps me a customer unfortunately.

There is a proper way to do this ... and an improper way to do this ...

ZenCoder

The proper way to do this is to have a click through notification! Also why would any web browser allow this without asking for permission first?

I switched operating systems and stop using corporate owned social media, I can definitely walk away from eBay without looking back.

If I can have honesty, it's easier to overlook mistakes.
-- Kirk, "Space Seed", stardate 3141.9