eBay is port scanning users' PCs

Windows PCs are scanned for remote support and remote access applications when visiting eBay’s website

When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works.

When users visit eBay’s website from a Windows PC, the site runs a script that performs a local port scan of the device to detect if any remote support or remote access applications are running.

As reported byBleepingComputer, many of the ports scanned by the online auction site are used for remote access and remote support tools including Windows Remote Desktop, VNC, TeamViewer and more. Upon further testing, the news outlet discovered thateBayis performing a local port scan of 14 different point when users visit its site.

The scan is conducted by a check.js script on the website that attempts WebSocket connections to a number of ports such as 3389 (Microsoftremote desktop, 5931 (Ammy Admin remote desktop), 6333 (VNC remote connection 7070 (real Audio andAppleQuickTime streaming) and more.

Oddly enough, the port scans do not occur when a user runningLinuxvisits eBay’s website, though the programs being scanned for are all Windows remote access tools.

Fighting fraud

Fighting fraud

As it turns out, eBay is conducting port scans of Windows PCs in order to detect if a compromised computer is being used to make fraudulent purchases on the site.

Back in 2016, multiple reports emerged revealing that cybercriminals were taking over users' computers throughTeamViewerto make fraudulent purchases on eBay. Since many of the site’s users use cookies to automatically login, the attackers were able to control their computers remotely and access eBay to make purchases.

In ablog post, Dan Nemec explained how he discovered that the script being used for fraud detection is actually from a product calledThreatMetrixwhich is owned by LexisNexis. While the programs eBay scans for when users visit its site are all legitimate, some of them have previously been used asRATsin phishing campaigns.

Are you a pro? Subscribe to our newsletter

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Fighting fraud is very important for eBay but at the same time, port scanning is still intrusive for its users.TechRadar Proreached out to the company for a statement regarding the matter but we did not hear back at the time of writing.

ViaBleepingComputer

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home.

Cisco issues patch to fix serious flaw allowing possible industrial systems takeover

Washington state court systems taken offline following cyberattack

Another reason to avoid edge-lit 4K TVs: they may fail faster than others, according to this report