eBay is port scanning users' PCs

(Image credit: Pixabay)

When users visit eBay's website from a Windows PC, the site runs a script that performs a local port scan of the device to detect if any remote support or remote access applications are running.

As reported by BleepingComputer, many of the ports scanned by the online auction site are used for remote access and remote support tools including Windows Remote Desktop, VNC, TeamViewer and more. Upon further testing, the news outlet discovered that eBay is performing a local port scan of 14 different point when users visit its site.

The scan is conducted by a check.js script on the website that attempts WebSocket connections to a number of ports such as 3389 (Microsoft remote desktop, 5931 (Ammy Admin remote desktop), 6333 (VNC remote connection 7070 (real Audio and Apple QuickTime streaming) and more.

Oddly enough, the port scans do not occur when a user running Linux visits eBay's website, though the programs being scanned for are all Windows remote access tools.

Fighting fraud

As it turns out, eBay is conducting port scans of Windows PCs in order to detect if a compromised computer is being used to make fraudulent purchases on the site.

Back in 2016, multiple reports emerged revealing that cybercriminals were taking over users' computers through TeamViewer to make fraudulent purchases on eBay. Since many of the site's users use cookies to automatically login, the attackers were able to control their computers remotely and access eBay to make purchases.

In a blog post, Dan Nemec explained how he discovered that the script being used for fraud detection is actually from a product called ThreatMetrix which is owned by LexisNexis. While the programs eBay scans for when users visit its site are all legitimate, some of them have previously been used as RATs in phishing campaigns.

Fighting fraud is very important for eBay but at the same time, port scanning is still intrusive for its users. TechRadar Pro reached out to the company for a statement regarding the matter but we did not hear back at the time of writing.

  • Also check out our complete list of the best VPN services

Via BleepingComputer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Biometrics add another layer of security to passwordless authentication
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
Forget AI – WhatsApp is planning a simple messages feature that could be its most useful upgrade in years
NordicTrack Ultra 1
The new NordicTrack Ultra 1 treadmill looks like it was designed by an architect and costs $15,000
An Nvidia GeForce RTX 5070
Nvidia RTX 5080 stock is so barren that retailers are holding competitions where you can "win" the right to buy one for MSRP