eBay scans your computer ports

Have you visited eBay recently? The site is a popular destination for buying new and used items. You will probably be surprised to learn that eBay scans your computer ports when you visit the site with one browsing.

You can verify it very easily. Use a browser such as Google Chrome, Firefox, Brave, Microsoft Edge, or Vivaldi. Open a new page and press the F12 key to open the Browser Developer Tools.

Open an eBay page on the Network tab in Developer Tools.

Wait for the page to load and look for 127.0.0.1 in the list of links. These are the scans that eBay runs when you log in to the site.

You can click on για να δείτε επιπρόσθετες πληροφορίες. Με αυτόν τον τρόπο θα δείτε την θύρα που σαρώνει το eBay αυτή τη στιγμή. Η σάρωση εκτελείται από το check.js, ένα JavaScript που εκτελείται στο eBay όταν οι χρήστες συνδέονται στον ιστότοπο. Χρησιμοποιεί WebSockets για να τρέχει τις αναζητήσεις στο τοπικό σας σύστημα χρησιμοποιώντας μια καθορισμένη θύρα και οι σαρώσεις πραγματοποιούνται ανεξάρτητα από την κατάσταση σύνδεσης.

The Bleeping created a handy table listing the ports:

Ebay NamePort (The Harbour District)
UnknownREF63333
VNCVNC5900
VNCVNC5901
VNCVNC5902
VNCVNC5903
Remote Desktop ProtocolRDP3389
AeroadminARO5950
Ammyy AdminAMY5931
TeamViewer TV05939
TeamViewer TV16039
TeamViewer TV25944
TeamViewer TV26040
Anyplace controlServices5279
AnyDeskANY7070

Most of these ports are used by remote connection applications, such as VNC, Teamviewer, or Windows Remote Desktop.

The Nullsweep website, which mentioned first this issue, found that the scan does not run on Linux systems.

It is unknown at this time why eBay is scanning its visitors' computers. Of course the reactions on Twitter and other social media sites are very negative. Users as a whole criticize eBay for scanning ports and for scanning ports as well as users who are not logged in to the site.

What can you do;

Block check.js script with a content blocker.
In some browsers, such as Firefox, turn off Web Sockets. EBay is loading script check.js from the following address (currently): https://src.ebay-us.com/fp/check.js

So a regex like || src.ebay-us.com ^ * / check.js should work fine.

The address can change and may differ if you log in from different addresses such as eBay.de.

The other option is to turn off WebSockets completely, but incompatibilities and upload problems may occur on other sites.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).