28 ms·
Why Is This Website Port Scanning Me?
- badRNG 6y agoThis raises the question: Is port scanning without consent a violation of the CFAA? Either it is legal, and researchers should face no repercussions for doing so, or it isn't and eBay is non-compliant with CFAA. I recall hearing about someone either being arrested or convicted due to port scanning a courthouse, but it was many years ago and I can't find the case with a cursory Google search. I have to wonder what value eBay would get from port scanning its customers. Is it part of an attempt to detect bots/attackers? Is malware running on their server trying to determine if the client is likely vulnerable to some propagation method?
- ajphdiv 6y agoNot illegal. Sites like shodan.io would have an issue if it was.
- bzb3 6y agoThat's a fallacious argument. The fact that someone is doing something doesn't mean it's automatically legal.
- TechBro8615 6y agoIANAL, but more likely it depends on intent and context. So shodan.io is okay because it’s not explicitly malicious, and they have clear paths to contact them if you suspect abuse. Whereas, if you’re suspected of hacking a website, the fact that you port scanned it a week prior to password spraying it might serve as evidence against you. That is, it seems unlikely anyone would be prosecuted for port scanning alone, but it could be an act that demonstrates intent of a later action. One time, I port scanned my public IP (of my ISP) from an EC2 box, and I got an email from EC2 saying they received an abuse complaint from the ISP for port scanning activity.
- pbhjpbhj 6y agoWhat's Shodan.io's legitimate use? Sounds like the "torrents can be used for legitimate content" type argument where in reality you a rounding error the use is not lawful??
- jerf 6y agoIf I were a serious baddie, I'd be afraid of using Shodan. Who knows who has what logging on that, and what honeypots may have been seeded into it for just such an occasion? It's not that hard to get that information yourself, from sources you control yourself. Legitimate usage from researchers and people reading about infrastructure they have the right to do security testing on may be a larger percentage than you think.
- 101404 6y agoI used to use torrents a lot and always for legitimate data transfers.
- pbhjpbhj 6y agoYes, I've used it to download Linux distros, but the point still stands.
- TechBro8615 6y agoThere are plenty of legitimate uses of port scanning, and specifically, a port scanning database like Shodan. For example: - Monitoring your own network or that of your clients for exposed ports - Researching Internet topology, or performing aggregate queries like “how many nginx servers are connected to the Internet” Can you use it maliciously? Yes. But, most of the time, if you have a target it would make more sense to do the port scan yourself. And if you’re just dragnet searching for vulnerabilities, most you find will probably already have been exploited. Sites like shodan are good for the overall health of the web because they force website owners to maintain security posture. If you know that foregoing a wordpress upgrade means you’re one script kiddy with a shodan account away from getting hacked, you’re going to keep your site up to date. This saves you from script kiddies, but also from the more sophisticated hackers who would run a port scan themselves anyway.
- ajphdiv 6y agoThe more pointed argument would be there is no federal law prohibiting port scans.
- TeMPOraL 6y agoDoesn't the Curl/For-loop Abuse Act (CFAA) cover it?
- wrkronmiller 6y agoIANAL but this type of websocket port scan seems inherently different from what Shodan does. Shodan is outside your network's firewall, therefore only able to access services you've exposed to the wider web. If I understand the article, the websocket scan eBay is doing is trying to connect to local listeners on your laptop, behind your network's firewall and possibly even behind your laptop's firewall.
- gnu8 6y agoThis is such an obvious consequence of web sockets that I wonder how anyone could have entertained the idea long enough to sober up and write the code. This is worse than letting a web page script have access to the clipboard, record mouse movements, and similar information leaks, because instead of just stealing information, now a web page can actively compromise any host on your network.
- crankylinuxuser 6y agoYep. Just waiting for this "feature" to be added to metasploit.
- wrkronmiller 6y agoI agree this is quite disturbing. It does not, however, sound like an attacker can establish arbitrary TCP connections (at least using the technique from the article). Instead, the attacker can determine if something is listening on a port because it will take a different amount of time to negotiate/drop a connection to a port when there is a listener than when there is not a listener. In other words, this sounds like a variant of a timing attack. As such, presumably, this particular avenue of attack can be mitigated by the browser vendor inserting a delay s.t. no information can be gleaned from how long it takes to negotiate/drop a websocket connection. EDIT: I also wonder if it would be possible to do a similar port scan using the timing of XHR requests to localhost (e.g. http://localhost:[port] http://localhost:[port]).
- throwphoton 6y ago
- JoelMcCracken 6y agoWas it this? https://news.ycombinator.com/item?id=21023023 https://news.ycombinator.com/item?id=21023023
- p410n3 6y agoThat wasn't port scanning. They actually physically went inside the building.
- badRNG 6y agoNo, I think it was probably close to a decade ago, but I likely am misremembering some of the details. Could've been a police department, but I'm not sure. That one you linked is a messed up case. There is a phenomenal podcast that interviews those guys and walks through their engagement. https://darknetdiaries.com/episode/59/ https://darknetdiaries.com/episode/59/
- p410n3 6y agoThis guy got arrested at least: https://www.securityfocus.com/news/126 https://www.securityfocus.com/news/126
- billme 6y agoArticle also states civil claims were dismissed - and criminal charges are unlikely to hold.
- relaunched 6y agoI hope they weren't debilitated by the legal fees incurred.
- badRNG 6y agonmap's "Legal Issues" section states that the guy went on to start a successful digital forensics company, after spending years crushed under 6-figure legal fees. https://nmap.org/book/legal-issues.html https://nmap.org/book/legal-issues.html Edit: Link to the company http://www.forensicstrategy.com/ http://www.forensicstrategy.com/ He also has a data recovery company now http://www.myharddrivedied.com/ http://www.myharddrivedied.com/
- nerdponx 6y agoMy guess is bot detection + user fingerprinting.
- dollers 6y agoSomeone's never caught a case. You may not think this is true but the way the legal system works is everything is illegal. Then when they need to get you you are already guilty. Everyone else they just ignore. Crazy, right? LMAO a downvote in 3 seconds. Good old hacker news. Well, downvotes don't make you right. I'm trying to open your eyes and you downvote me. I guess that is to be expected.
- paulryanrogers 6y ago"Innocent until proven guilty" suggests that everything is legal unless there is a law against it.
- MaxBarraclough 6y agoNot quite the same thing. A legal system could use presumed guilt (defaulting to assuming an accusation is true) while still having a 'blacklist' approach to which actions are punishable. https://en.wikipedia.org/wiki/Everything_which_is_not_forbidden_is_allowed https://en.wikipedia.org/wiki/Everything_which_is_not_forbid...
- crankylinuxuser 6y agoIt doesn't make any sense in trying innocent people! (No, seriously, I know people who believe that.)
- pdonis 6y agoDo you know how many laws there are? Not to mention common law, which is law established by previous court decisions on matters that have never been covered by any statute?
- throwaway023421 6y agoOver the years I've seen "hacker" news become more of an echo chamber and instantly downvote anything against doctrine... I'll be downvoted for saying this.
- 6y ago
- duxup 6y agoWhen did networking support we often had old code + lower quality equipment that could / would crash if you used off the shelf security software that would go out and scan and then try all sorts of things and then generate a report. I'd say 90% of the time the powers that be at the company had no idea someone was running that software, or that it was still running at their company, and then someone moved a firewall and the system was exposed to more than intended. Then they'd turn it of ... and find another similar tool running somewhere else. It could be a simple as a test or security system run amok.
- mcny 6y ago> I'd say 90% of the time the powers that be at the company had no idea someone was running that software, or that it was still running at their company, and then someone moved a firewall and the system was exposed to more than intended. Then they'd turn it of ... and find another similar tool running somewhere else. This demonstrates the absurdity of the CFAA more than anything else. Sorry for sounding like a broken record but the CFAA is not salvageable and MUST be repealed.
- wrkronmiller 6y ago> I have to wonder what value eBay would get from port scanning its customers. From the article: > Looking at the list of ports they are scanning, they are looking for VNC services being run on the host, which is the same thing that was reported for bank sites. > VNC is sometimes run as part of bot nets or viruses as a way to remotely log into a users computer. There are several malware services that leverage VNC for these purposes.
- deleted 6y ago[deleted]
- bitdivision 6y agoThey're almost certainly doing it as part of a heuristic to detect bots. Hence the VNC / RDP ports. I would assume it's quite common for bots to have those ports open so they can be monitored
- hn_check 6y agoIn this case it's a script running on your own web browser that's scanning localhost. You are effectively scanning yourself. It's in a different realm from external scans.
- kube-system 6y ago> Either it is legal, and researchers should face no repercussions for doing so, or it isn't and eBay is non-compliant with CFAA. Criminal law is usually not this simple, as most criminal laws will take into account the mental state of the person performing the action.
- rtkwe 6y agoIt's probably part of their fraud detection and mitigation strategy. Combined with other info about your transactions it could help raise a flag about changes. As for the CFAA that's seemingly down to how aggressive the prosecutor is feeling about your case. I don't think it should be there's no real access happening and unless it's extremely aggressive and degrades network connectivity it's hard to argue there's any real damage done.
- hedora 6y agoBypassing a firewall to run a port scan is almost certainly illegal. That’s what these sites are doing.
- tptacek 6y agoAlmost certainly not. Commercial unauthorized port scans are utterly routine. There are well-known companies premised on it. You can get to the same answer axiomatically from the text and case history of CFAA (a port scan literally can't grant you the access a CFAA claim needs to prove you intended), but that's obviously treacherous for non-experts to do; instead, the empirical demonstration should be conclusive here. I don't know why this scan is occurring, but fingerprinting is the most obvious guess, and intrusive fingerprinting performed by real companies is usually about ATO prevention, which means they're not going to tell you any more about it (ATO defense is an arms race).
- laurentdc 6y ago> Furthermore, when I installed and ran a VNC server, I didn't detect any difference in site behavior - so why is it looking for it? I think behind the scenes they keep log of some sort of fraud risk, e.g. geoip different from billing country, suddenly a new operating system, vnc/teamviewer running would probably flag your account (even for benign purposes, e.g. you can get your money back or purchase cancelled if that info can prove your transaction was actually unauthorized). I worked on a ecommerce where the previous developers implemented a rudimentary "score" system like that so that suspicious orders would be put in queue for phone verification (this was pre gdpr)
- BCharlie 6y agoThat makes a lot of sense. I assumed it was somehow for anti-fraud, though I still don't like it.
- 2009guy 6y agoBest to log all scanning attempts...
- 2011guy 6y agoBest to keep a log of all scanning events...
- 637474859 6y agoI’ve been port scanned myself...
- kgersen 6y agoport scanning is fine and should not be illegal. It's just "looking" at a house to see if there is a door and what type of key (protocol) it uses. Trying to open a connection on the other hand it's like trying to open the door. That should be considered as a violation.
- pfundstein 6y agoMost port scanning works by 'Trying to open a connection'. I'm not sure where you're saying the line is, but it's very fuzzy.
- woadwarrior01 6y agoPort scanning from an external host is fine and dandy, but doing it on localhost from the user's browser crosses the line, IMO.
- crankylinuxuser 6y agoThen why did your "user agent" permit it? Seems rather anti-user.
- corentin88 6y agoImagine you start to look at houses in your neighborhood « to see if there is a door and what type of key it uses ». That sounds pretty suspicious to me. At least you need the consent of the house’s owner.
- xur17 6y agoIs there a way to block this at the browser level? Ex: block access to localhost for all domains (except from localhost itself)?
- edoceo 6y agoWhitelist sites that you allow WS features.
- bilekas 6y agoI wonder though if it was just a websocket that could do this, surely some client side JS can just itterate the same when loaded.
- chippy 6y agoCould you expand upon how to do this? And what does WS mean?
- bilekas 6y agoWS is WebSockets, its a protocol so you could disable it at that level.
- bilekas 6y agoWas thinking the same, maybe creating a service account for the browsers, I believe they do need some level of elevation but then using the firewall rules disabling everything expect http/s ports.. Websockets and others might be an issue, might need to be updated on an adhoc basis though and shouldnt be the reposonsibilty of the users. This is kinda gross practice overall.
- inetknght 6y agoUse uMatrix and set a global block.
- anarcat 6y agospecifically, websockets are blocked by the "XHR" component on the popup panel, which also blocks XmlRPC and the Fetch API. as a rule, you could block all XHR requests everywhere with: * * xhr block What I actually do is block everything but first-party requests, apart from CSS and images: * * * block * * cookie block * * css allow * * frame block * * image allow * 1st-party * allow * 1st-party css allow * 1st-party frame allow * 1st-party image allow i actually allow xhr on third-party requests once i enabled third-party requests, which makes it possible to "enable" a bunch of site with two clicks (popup panel then click on "all").
- relaunched 6y agoThis use doesn't seem to be covered by eBay's privacy policy https://www.ebay.com/help/policies/member-behaviour-policies/user-privacy-notice?id=4260 https://www.ebay.com/help/policies/member-behaviour-policies...
- blakesterz 6y agohmmm, so the conclusion is: "Whether the port scan is used as part of an infection or part of e-commerce or bank "security checks", it is clearly malicious behavior and may fall on the wrong side of the law." Though I really don't know what ebay or banks or any site might be doing, it seems like it's almost certainly a defensive thing looking for signs of trouble. I don't know if I'd call it malicious. Isn't this totally harmless in this case? That is, eBay portscans me, how is this malicious?
- the8472 6y agoYou don't know whether they're collecting the data and running analysis on it. What services you're running may already reveal something about you.
- souterrain 6y agoThe greater issue is that browsers are allowing code executing from the public Internet scope (scope meaning security domain) network access to the localhost scope or the Intranet scope (RFC1918 addresses.) If anything, this should require very explicit permission granting from the user. I’d prefer it be something more like an undocumented toggle accessible solely to developer types.
- api 6y agoYeah, that's the best solution. It should be like microphone or camera access. It should say "this web site is attempting to access a resource on your local system / network." I don't think you need to overdo it in terms of making the warning red, etc. Just a popup will really discourage people from trying to use this for fingerprinting. BTW the site says: "Port scanning is malicious." I don't agree. There are many many things that can look like a port scan but are not malicious, most notably NAT traversal attempts by WebRTC, games, chat apps, and so on.
- grendelt 6y agoRight. "it is clearly malicious behavior and may fall on the wrong side of the law." It's not against the law. It might be _shady_ but it's not illegal. When I'm teaching cyber intro classes, I let folks know portscanning is NOT illegal but shady. It's like going to a business after hours. It's not illegal to rattle doors and windows to see if they're locked. The police might have a different take on it, but it's not illegal.
- fossuser 6y agoYeah - if anything this post is evidence of a use case that isn't malicious. While it can be used to get information to bad things, it itself can be used for good things too.
- alex_duf 6y agoAgreed, or at least disabling localhost and 192.168.0.1 and whatever that is in IPV6
- maayank 6y agoIf anyone thinks of implementing this, don't forget to guard against reflection attacks[1] EDIT: revisiting my comment (and the wikipedia article linked), a reflection or amplification attack in this context is sending traffic and generating (perhaps much more) traffic from a different source than yours as part of an attack. For example, you could spoof the IP address of the HTTP packets and cause the server to port scan another machine -> little traffic (HTTP request) causing a lot of traffic (port scanning). As part of a DDOS attack, a botnet for example could use this to amplify their attack and masquerade the source. [1] https://en.wikipedia.org/wiki/Denial-of-service_attack#Reflected_/_spoofed_attack https://en.wikipedia.org/wiki/Denial-of-service_attack#Refle...
- Jonnax 6y agoBrowsers should be blocking this by default. "This website is trying to access services on your local PC, do you want to allow?" Or at least as blockers should have a rule for it.
- osolo 6y agoMy kids complained today that Google Classroom isn't working. After a quick investigation, I noticed that Snort on my firewall blocked the relevant Google server due to incoming TCP port scans. Sigh.
- BCharlie 6y agoYikes! Maybe that's the next thing I will take a look at...
- r1ch 6y agoBe careful with automated rules - unless it's a full TCP handshake, you can't conclusively identify the source of a port scan as the IP may be spoofed. If someone port scanned you and spoofed eg the IPs of your DNS servers, you've self-DoSed yourself.
- driverdan 6y agoCan you share the server IP / hostname?
- discreditable 6y agoFrom the title I assumed this was going to be something else. I remember some sites used to port scan you on registration. This was to check if registrations were from an open proxy, which was a very strong bot indicator. I might be misremembering but I think Slashdot used to do it. There were also some plugins for phpBB forums that did it too. I used one back in the day and it helped quite a bit with spam registrations.
- machello13 6y agoHow did port scanning work back then before WebSockets?
- r1ch 6y agoThese were external scans - see if the visitor's IP is running an open SOCKS or HTTP proxy for example. Many IRC networks still port scan you on connect for the same reason.
- deleted 6y ago[deleted]
- Deimorz 6y agoYes, I definitely remember Slashdot doing it, but it was more often than just on registration. Here's an article from 2014 about it, which says that it happens on every login and posting a comment: https://soylentnews.org/article.pl?sid=14/04/09/1925245 https://soylentnews.org/article.pl?sid=14/04/09/1925245 At the bottom of that post it says the code was added on 2008-04-16 19:07:46 +0000.
- discreditable 6y agoThat sounds right. To test I ran a capture on my gateway and it seems like they aren't scanning 8080 or 3128 on login or post nowadays.
- bjt2n3904 6y agoEvery time I hear about some shiny new feature being added to a browser, I think... 1) Will I ever actually use this 2) How is this gonna screw me over WebSockets, WebBluetooth, WebAssembly, Web-You-Can-Access-my-Accelerometer-and-Battery, haven't ever wanted to use those. Ever. For anything. For any reason. (Edit 3: Oh yeah, I forgot! WebRTC!) Edit: Fantastic. You can't disable it in Firefox. So what, does Firefox need a freaking iptables implementation now? [1] 1 - https://bugzilla.mozilla.org/show_bug.cgi?id=1091016 https://bugzilla.mozilla.org/show_bug.cgi?id=1091016 "The only theoretical reason for the WebSocket pref these days is the possibility to disable it easily in case there is a security issue found in the protocol itself or so." The protocol itself is the security issue. ALL OF IT. Edit 2: So I don't have the time to investigate every new fad when it comes out. I originally thought WebSockets were raw sockets, but they aren't. Firefox blocks access to port 22 -- I was hoping all privileged ports, but it seems just those. Opening a WebSocket to netcat dumps out a HTTP request, so it seems unlikely that you'd be able to talk with anything that doesn't talk HTTP and WebSockets. Firefox also seemingly blocks access to 192.168/24 and 10/8. This makes me less angry. But what STILL make me angry is that I have to sit and research about some stupid thing that I don't want and can't turn off. Sooner or later, some web dev is gonna argue that all sites should be loaded over WebSockets because his bloated javascript stack performs marginally better, and then WebSockets won't be something I can turn off. Websites will just whitepage. Edit 4: Done researching this now. I went to ebay on Firefox, and wasn't getting websocket scans. But I've got a stack of uBlock and NoScript... maybe that's interfering with it some how? Opened up a stock config for google-chrome -- that's my browser for "some dumb new web tech that isn't working in Firefox" -- not seeing any scans when I open up inspector and click "WS". Regardless, his point still stands. You can totally use WebSockets as a port scanner for localhost, assuming the Content Security Policy allows it. Now I gotta go update my nginx configs...
- deleted 6y ago[deleted]
- the8472 6y ago> So what, does Firefox need a freaking iptables implementation now? umatrix is the layer7 firewall you're looking for, it can block websocket connections, cross-domain ones in particular are quite easy.
- JaceLightning 6y agoPoorly written article: mixes facts and opinions > it seems many sites are port scanning visitors for dubious reasons. Claims that in the intro, but then admits ebay is scanning for VPNs, which probably means it's doing fraud detection, which is definitely not a dubious reason, and is probably actually beneficial to the customer.
- fareesh 6y agoWhy is localhost / 127.0.0.1 allowed from a remote JS file without any permissions?
- owaislone 6y agoThis is scary. I've always left locally running services unprotected for convenience given they can't be accessed from outside. I can imagine a lot of people running local apps, servers or databases without any auth that could contain sensitive information. Would a webpage be able scrape data from such services? Any way to disable this completely in Firefox and Chrome?
- dvdkhlng 6y agoNo, webpage javascript is limited to using websocket protocol [1] for connections. That means your database or IP camera, or VoIP phone or router are safe for now. Though the websocket connection establishment seems to allow the javascript to differntiate between a closed and an open TCP socket and a TCP socket that speaks websocket. [1] https://en.wikipedia.org/wiki/WebSocket https://en.wikipedia.org/wiki/WebSocket
- owaislone 6y agoSo if a local service allows WS connections, can data be scrapped off such a service?
- dvdkhlng 6y agoYes, the primary (or only) reason to even implement a WS server connection is exactly to allow data to be scrapped off using a web-browser. E.g. Asterisk nowadays allows enabling SIP protocol access over websocket so that you can run a javascript VoIP client from inside a browser [1] (and WebRTC for the media layer). [1] https://wiki.asterisk.org/wiki/display/AST/Asterisk+Builtin+mini-HTTP+Server https://wiki.asterisk.org/wiki/display/AST/Asterisk+Builtin+...
- owaislone 6y agoSure but such servers would always implement authentication when deployed to the web but a lot of such services could run locally unauthenticated to serve local apps. For example services to power electron apps. This tells me data from such services can be stolen very easily.
- annoyingnoob 6y agoIf the bank is checking on my security then its reasonable for me to check the security of the bank, right?
- kchr 6y agoCheck the bank EULA. You might have agreed to the scans without knowing.
- gfxgirl 6y agoThis is bad and should be blocked IMO, at least by default, but can a site do anything other than find out which ports respond to a websocket request? AFAIK they can't send arbitrary network packets. The websocket will only open if the port they are trying to talk to speaks websocket back. This is mentioned in the article. I'm not saying that's okay. I still don't want them scanning ports on my machine. There might be some services that offer a websocket connection like Plex for example, or the Kinect driver, or Leap Motion. I also don't want them cataloguing ports that are open.
- foobarplopp27 6y agoThis guy Just has it wrong when he calls port scanning an adversarial technique. It's Just a way to discover Services. You can then use the result to do malicious things but it's not like the only or even main purpose. I humbly refer to this: https://koeln.ccc.de/ablage/portscan-policy.xml https://koeln.ccc.de/ablage/portscan-policy.xml (Google translate can help with the german)
- xg15 6y agoTo my knowledge, a lot of effort has been put into the design of CORS (and related APIs) to specifically prevent misuse like that. A well-behaved Websocket implementation should not give the calling script any indication why a connection failed. I know timing oracles are difficult to avoid in many cases - but the technique shown here seems to actually exploit different kinds of exceptions being thrown by the browser. This seems like a straight-up bug and pretty serious security vulnerability to me.
- MrStonedOne 6y agocors/csp allow the webpage owner to control what servers the javascript running on on their webpage can access and allow web servers to control what 3rd party websites make requests to them. Notice the missing piece? Neither of those allow the user to control these things. At the end of the day, it is reasonable to assume that localhost access is a valid security barrier in the general networking sense. Making an exception for certain types of networked applications is just adding a pitfall for some dev to fall into. Good process design has to take into account the inevitability of human error, and leverage things like "forget safe" rather then "remember safe" (forgetting a step should fail safely, with an error or incorrect but still safe behavior, then unsafely, with an exploit or an explosion) Using websockets or XHR to transverse internet firewalls is browsers transversing security barriers as a feature, and needs to go the way of the mic access, with a per-site prompt.
- crazygringo 6y agoFirst of all, fraud detection seems like a legitimate use case here. And WebSockets has many valid uses. HOWEVER -- how the hell is localhost port scanning allowed to happen without my permission?! This feels no different from a website trying to check the existence of named directories on my file system or something. Does WebSockets not require permission to function at all, or shouldn't it be limited to some kind of CORS-type policy or something to connect without a permissions dialog? Or even if it's allowed to port scan the entire public internet, at least block your local machine and network without explicit permission?
- ryan-allen 6y agoIf you find a way to prevent this in Chrome/Edge please let me know. Edit: https://defuse.ca/in-browser-port-scanning.htm https://defuse.ca/in-browser-port-scanning.htm There doesn't seem to be a way to access anything locally, just test for open ports. I use SSH tunneling a lot and was having a minor freak out.
- _bxg1 6y agoI don't follow what this has to do with websockets specifically; they just go over HTTP, so why couldn't you do this with a regular HTTP request? Either way it seems easy to mitigate at the browser level: block all requests to localhost that don't originate from a page served on localhost. It's not that different from the CORS policy.
- zlynx 6y agoIf you want analogies, this is like walking into a bank to do business and the security guard checking to see if you're wearing a mask.
- tryauuum 6y agoPeople are good at inventing analogies that support their point of view.
- barbarbar 6y agoSo if disable javascript - it will not be possible?
- thanksforfish 6y agoSee also: BeEF[1] Theres lots of scanning/attacks you can do using the web browser as your scanning tool. Its troubling that major sites are starting to use some of these techniques, but these techniques have been readily available to attackers with open source tooling. I think it's long overdue for browser to find a way to mitigate these sorts of attack vectors. If the security folks can't justify it due to BeEF, maybe the privacy folks can using articles like this. [1] https://beefproject.com/ https://beefproject.com/
- lucaserb 6y agoI downloaded Brave for the first time today after reading this.
- akerro 6y agoInteresting, port scanning is illegal in some countries as it's classified as security testing, it can be only performed with permission. How would you feel is someone was walking on busy car parking and checking if doors of the cars are open? It' what port scanning is, checking if the car has open door.
- kchr 6y agoIs opening car doors illegal if you never enter the car/steal anything?
- ac29 6y agoA motivated prosecutor could almost certainly find something to throw at you - some variety of public nuisance law or something.
- clarry 6y ago> How would you feel is someone was walking on busy car parking and checking if doors of the cars are open? It' what port scanning is, checking if the car has open door. More like sending a "hi, can I enter?" signal to a self-driving taxi that has been left waiting in a public arena. Don't put a server online with a public IP if you don't want to receive those signals. Don't send "hi yes you can enter!" responses when you get the query, if you don't want to let people in.
- jgwil2 6y agoExcept in the case described by the article, the port scanning is being done not on servers on the public internet but on clients of certain websites.
- lucaserb 6y agoDownloading Brave Browser right now...
- jcoffland 6y agoPort scanning localhost from a webpage has been possible for a long time and does not require websockets. http://jsscan.sourceforge.net/ http://jsscan.sourceforge.net/
- segfaultbuserr 6y agoIt's why Tor Browser restricts access to localhost by default. This problem was already predicted and considered by Tor developers back in 2014, see ticket #10419 - Can requests to 127.0.0.1 be used to fingerprint the browser [0] and has been fixed since then. Scanning localhost is a dangerous way to fingerprint the user if there are local open ports. If you are not using Tor Browser and want to fix the security hole without disabling WebSocket completely, running the web browser in a separate network namespace is a workaround - you get a loopback interface which is independent from the main namespace, and you create a NAT interface within the network namespace to allow outgoing traffic. It's also a possibility for a website to probe other machines, such as the setting page on your router. For better protection, you should block all the local addresses defined by RFC1918 via netfilter/iptables as well. For developers who needs less restrictive blocking for debugging, you can run multiple Firefox processes in different profiles (firefox -P --new-instance), each running in a different network namespace - to make it easy, you can code everything in a shell script and create desktop icons for them. I normally use an ad-blocked and 3rd-party-cookies-blocked profile for web browsing, but a naked Firefox profile for development. [0] https://trac.torproject.org/projects/tor/ticket/10419 https://trac.torproject.org/projects/tor/ticket/10419
- gsnedders 6y ago> It's why Tor Browser restricts access to localhost by default. This problem was already predicted and considered by Tor developers back in 2014, see ticket #10419 Sorry to invoke the meme, but Opera did it first[0], in Opera 9.50 (2008). I don't have a good reference to hand, but [1] is a developer complaining about this. [Edit: [2] covers the feature in some detail.] Opera also blocked access to private IP addresses (so there were three tiers: public IPs, private IPs, localhost; higher tiers could communicate with lower ones, so the block was only unidirectional). IE10+/EdgeHTML-based-Edge (and I know there was some talk about blocking this in Chromium-based Edge) also blocks it, so that too is prior art to the Tor change. [0]: https://w3cmemes.tumblr.com/post/62942106027/if-you-can-think-of-it-its-999-likely-opera https://w3cmemes.tumblr.com/post/62942106027/if-you-can-thin... [1]: https://stackoverflow.com/questions/1836215/access-to-127-0-0-1-by-default-in-opera-10 https://stackoverflow.com/questions/1836215/access-to-127-0-... [2]: https://web.archive.org/web/20140302021701/http://my.opera.com/securitygroup/blog/2012/07/03/operas-cross-network-protection https://web.archive.org/web/20140302021701/http://my.opera.c...
- XaspR8d 6y agoThis does suggest to me that browser websocket requests against localhost should at least: 1) return the same error message for all failures (unless some opt-in / launch flag is set) 2) fiddle with the timing slightly to make timing attacks less useful? (how long is a localhost TLS connection? 100ms? I think devs can wait a handful of frames for their failure response.) I have no idea how many legitimate apps are leveraging some kind of localhost connection -- it sounds like an unusual use case but I can certainly imagine some enterprise app that ties into desktop services or programs by that route. EDIT: Of course banning them outright or requiring specific user whitelisting of domains would work as well. Just trying to get away with the smallest change.
- skizm 6y agoIs there a setting or something in either chrome or FF to block websites from being able to port scan you?
- upofadown 6y agoSupposedly you can disable websockets in Firefox by setting network.websocket.max-connections in about:config to 0.
- superkuh 6y agoPort scanning isn't malicious behavior. Port scanning is about equivalent to walking down the street and looking at the architecture of the buildings.
- pdonis 6y agoYour analogy might apply to a port scanner running over the Internet and looking at what ports are open on Internet-facing servers. (Though I would still argue the analogy is flawed there: port scanning Internet-facing servers is more like going up to each locked door on the street and writing down what kind of lock it has, in case you want to try to pick it later.) But a port scanner running inside the browser on my local machine is equivalent to someone sneaking into my house and going through each room seeing what valuables are there.
- superkuh 6y agoI agree. It's foolish to give websites permission to do that kind of thing. There's a very simple solution: don't give them permission. Turn off javascript. Yes, ebay will complain but it'll still work. The power is in your hands. No one is forcing you to use eBay either. Giving arbitrary websites the ability to run arbitrary code on your machine is just asking for trouble. It's like someone who opens and executes every email attachment they receive. Try out NoScript temp-whitelist only mode that blocks by default and requires manual permission giving.
- clarry 6y ago> (Though I would still argue the analogy is flawed there: port scanning Internet-facing servers is more like going up to each locked door on the street and writing down what kind of lock it has, in case you want to try to pick it later.) I disagree, there is no security mechanism in port numbers. It's just a door that opens for you or not. Checking whether a door opens for you does in no way imply that you're perhaps planning a crime.
- fgnewsom 6y agoFUCK GAVIN NEWSOM!
- thisisnot 6y agoin firefox it seems you can disable websocket with network.websocket.max-connections = 0 Firefox and the illusion of privacy (1)https://www.remembertheusers.com/2018/03/0455-firefox-and-the-illusion-of-privacy.html https://www.remembertheusers.com/2018/03/0455-firefox-and-th...
- dawnerd 6y agoeBay must have some logic to determine who to scan. I can't get it to trigger on my windows desktop or mac.
- tonymet 6y agoanyone know the config or flag in Chrome to disable any requests to localhost? Ideally excluding origin=localhost, but if not possible i can dev on a different account
- jolmg 6y ago> Port Scanning is Malicious Though port scanning can be (and maybe even frequently is) done with malicious intent by looking for misconfigured/bugged servers, I disagree that it's inherently malicious. Port scanning is just about checking to see what services a host is offering you. It's like going to a random shop at a mall and asking what services they provide. Would asking about their services be malicious? It feels like the reason asking about services is considered malicious is because shops frequently give out info to the public that they shouldn't have. It's like: client: What services do you provide? shop owner: Well, I can provide you with a list of all my clients along with their personal information they entrusted to me. So, is the client being malicious for asking or is the shop owner the one that was in the wrong for mistakenly providing that info to the public? I feel the only reason we don't blame the shop owner is because even though he's the one that mistakenly discloses private info, sometimes he's just following a script written by a random programmer unassociated with him. Maybe the response was a mistake on the programmers part, maybe it was a mistake in how the shop owner used the script (a configuration error). In the end, it's simpler to blame the client for asking out-of-the-box questions (after all, most clients just come in to ask if you're giving out flyers/pamphlets because that's what everybody does) and so they don't feel responsible for the response that results. I can provide a shop that also offers things different than http(s) with open access to the public. It shouldn't be a crime/violation to ask me if I offer them.
- Cakez0r 6y agoI think it's a bit more like going on to a shop and trying to open all the doors, cupboards and drawers to see which ones are locked ;)
- jolmg 6y agoThat's a bad analogy. It wrong because you can see what doors, cupboards and drawers are available for the public. Doors that are in-reach but that shouldn't be used by the public have signs like "restricted access" or "employees only". You can't do that with the internet. You can't see that a port is not available to you until you try it. If you want to continue using that analogy, then you have to consider that everybody is blind and deaf, and checking to see what's locked is the only way to know if something is available.
- Giorgi 6y agoI don't think motivation is malware detection, I am assuming this is sort of fraud detection (like carding)
- braxxox 6y agoPort scanning from a web page, combined with DNS rebinding, can present a really nasty attack, and can effect an entire private network, not just localhost. Some more info here: https://medium.com/@brannondorsey/attacking-private-networks-from-the-internet-with-dns-rebinding-ea7098a2d325 https://medium.com/@brannondorsey/attacking-private-networks... Example code: https://github.com/brannondorsey/dns-rebind-toolkit https://github.com/brannondorsey/dns-rebind-toolkit A malicious DNS rebind server: https://github.com/brannondorsey/whonow https://github.com/brannondorsey/whonow Disclaimer: I performed some of this research a few years ago. So those resource suggestions are my own, but they feel very relevant here.
- brainzap 6y agoThis is why the websocket implementation does not have meaningful error codes, so people can not abuse it. But they still do.
- awinter-py 6y agoTLDR because you have javascript enabled
- parliament32 6y agoLots of chat in the comments about how this is all websockets' fault, but don't forget you can portscan localhost with pure JS as well. https://portswigger.net/research/exposing-intranets-with-reliable-browser-based-port-scanning https://portswigger.net/research/exposing-intranets-with-rel...
- carapace 6y agoAch! That's diabolical.
- gsnedders 6y agoTiming attacks make it very hard to prevent port/host probing generally, sadly, with the sheer number of things that are observably loaded cross-origin (iframes in that example, but also images, scripts, stylesheets…). (In the private/loopback IP ranges we should really just make those requests always fail, but I addressed that in another comment as to why that's not trivial.)
- parliament32 6y agoPrivate and loopback space should really be outside the sandbox, or at least in a permission. I'm happy with mycorp.net accessing 10/8 space, but not ebay.
- anderspitman 6y agoCurious what HN thinks about this hypothetical: Imagine you have a web app designed to talk to a specific backend server API. It's also common for users to run instances of the server on their local machine. How would you feel about the app checking a (single) well-known port to see if there's a local server running, and prompting the user: "we detected you're running a local copy of the server, do you want to connect to it?" This doesn't seem to be done very often, and the public cases usually seem to be pretty ugly (Zoom). But I could see it being useful. Imagine for example an app for browsing S3 directories, that could also detect if you're running a minio server and allow you to connect to it, and transfer data back and forth between your different backends.
- CobrastanJorji 6y agoI don't think the case that you're describing is unethical, but I also don't see it as beneficial enough to outweigh the security risks of it being possible.
- swalsh 6y agoI can think of a legitimate use case for this. If you watch some of these scammer youtube videos, one common thing they seem to do is get on a screensharing application, and have the user log into their bank account. From there, the scammer inspects the html, and manipulates the values to trick the victim. A bank knowing if someone else is watching your screen is a decent security measure.
- splonk 6y ago> Furthermore, when I installed and ran a VNC server, I didn't detect any difference in site behavior - so why is it looking for it? Not an eBay employee, but used to work in fraud detection. Two very obvious related guesses from my experience: 1. Fingerprinting a user to help identify account takeover (ATO). Open port signatures is probably a pretty good signal for that kind of thing (and it doesn't seem to be measured in https://panopticlick.eff.org/ https://panopticlick.eff.org/). > However it is also a valid tool used by administrators for remote access to machines, or by some end user support software, so the presence of VNC is a poor indicator of malware. 2. In a Bayesian sense, this probably isn't right. I don't know what eBay's traffic looks like but I'm willing to bet that all other things being equal, traffic coming from a machine with an open VNC port is riskier. Fraud detection is a game of probabilities, so the existence of a valid user showing a particular characteristic doesn't mean that the characteristic isn't useful in a fraud model. The example I always give is that when I was doing this (quite some time ago), we could have had a 99% accuracy rate for a simple rule banning IPs from Turkey, Ghana, Nigeria, and Vietnam. It's not because there weren't any valid users from those countries, it's just that the fraudsters where overwhelmingly likely to be using IPs from those countries.
- gfxgirl 6y agopanopticlick is specifically about browser fingerprints. It doesn't include your IP address for example.
- loa_in_ 6y agoCan you say what were the final false positive rates? Was this part of your research?
- thejynxed 6y agoThose four are still considered untrustworthy, and I've had to add India, Ukraine, and Brazil to the list of nations I filter entirely.
- jquast 6y agoSee also, http://localrouter.net/ http://localrouter.net/
- jamesfisher 6y agoPotentially you can do more than just port scan; it's possible to use/access the servers that you have running on your local machine if they're left open. See my post about this: https://jameshfisher.com/2019/05/26/i-can-see-your-local-web-servers/ https://jameshfisher.com/2019/05/26/i-can-see-your-local-web...
- pknerd 6y agoI just tried myself and could not find any such thing. MAy be a bug or removed after seeing it featured on HN?
- TekMol 6y agoWhen you do this: new WebSocket("ws://127.0.0.1:8080") An application listening on 8080 is indeed getting a packet delivered. Run this to see the packet: nc -lp 8080 And the page can figure that out via the error returned. I wonder if that is in line with the same origin policy. On the other hand, maybe the same is possible by creating an image with src="http://127.0.0.1/hello.jpg" http://127.0.0.1/hello.jpg" and looking at the onload/onerror event?
- cygx 6y agoBut note that a simple <img src="http://127.0.0.1:8080"> should do so as well, ie this is just the newest iteration of an old problem that the major browser vendors never chose to properly address - with the exception of Opera, see eg this stackoverflow question [1] and corresponding answer from 2011. [1] https://stackoverflow.com/questions/5464599 https://stackoverflow.com/questions/5464599
- TekMol 6y agoThe page could never read the contents of the image, right? If the user has a web-socket-server running (for example because he is a developer) could the page read from it? Can a page read from any web socket server on the internet?
- cygx 6y agoIf the user has a web-socket-server running (for example because he is a developer) could the page read from it? Only if that server chooses to accept the request, which it can decide based on the Origin header. Personally, I was more concerned with getting spurious requests on ports bound to 127.0.0.1 (which I've been using for IPC), but that issue already existed before the introduction of WebSockets. WebSockets of course do make things like port scanning easier, but as others have pointed out, you could already do that with a bit of ingenuity eg through tracking response times.
- paddlesteamer 6y agoActually , I'm pleased ebay is doing this. It wasn't a new issue but now ebay doing it, it took a lot of attention. It's like disclosing a security issue in WebSocket protocol. Now I'm sure next releases of the most browsers will fix it.
- null4bl3 6y agoNow scanning for open ports I can do on Linux. But how would I go about monitoring which ports are being scanned on Linux? No tool doing this comes to mind
- homami 6y agoHow does it work in practice? It seems in Chrome these errors cannot be caught try-catch blocks. try { var socket = new WebSocket('ws://localhost:808'); } catch (ex) { console.log(ex) // control does not reach here }
- mdouglass 6y agoIt probably fires as an async error, I'd expect this would log it (if inserted at the end of the try block): socket.onerror = (...args) => console.log('async error', ...args)
- homami 6y agosocket.onerror event happens for both cases. But there does not seem to be any difference between the error object that is passed to the these handlers.
- m3047 6y agoApropos past issues with Zoom installing a local server, this is important to consider.
- 3fe9a03ccd14ca5 6y agoHow do I prevent this? Is there something I can do to block localhost (RFC 1918) port scanning?
- azinman2 6y agoAny suggestions of ways to block this? Any Safari extensions?
- bosswipe 6y agoJavascript was a mistake, seriously. The benefit-cost ratio from the user's point of view is disastrous. I'd rather slog through less fancy data entry forms than suffer endless tracking, privacy and security attacks.
- drbenway 6y agoI've noticed many of the survey for cash sites use websockets to scan for running services on your machine Personally I think its straight up evil
- folmar 6y agoThose are natural abuse (automation) targets so always used a lot of tracking.
- sitkack 6y agoI can't believe of the 363 comments no one has mentioned Samy K and his awesome Poisontap project. Parts of which did this local scanning and connecting to your internal router management page. https://github.com/samyk/poisontap https://github.com/samyk/poisontap See also, https://www.theregister.co.uk/2010/01/05/geo_location_stealing_hack/ https://www.theregister.co.uk/2010/01/05/geo_location_steali...
- csagan5 6y agoThere is an open Chromium bug for this: https://bugs.chromium.org/p/chromium/issues/detail?id=378566 https://bugs.chromium.org/p/chromium/issues/detail?id=378566 I hope they consider it still valid and not close it. These are the blocked ports: https://github.com/chromium/chromium/blob/83.0.4103.53/net/base/port_util.cc#L22 https://github.com/chromium/chromium/blob/83.0.4103.53/net/b... Accessing localhost and LAN addresses works perfectly fine, except for those ports. I am going to patch Bromite so that it doesn't allow any access to localhost nor private networks.
- csagan5 6y agoInterestingly enough they are already blocking these attacks for background requests, see https://github.com/chromium/chromium/blob/83.0.4103.53/third_party/blink/renderer/modules/background_fetch/background_fetch_manager.cc#L251 https://github.com/chromium/chromium/blob/83.0.4103.53/third... Perhaps they simply forgot to cover also the WebSockets case, or the discussion on the related bug was not allowing for expanding the coverage.
- rurban 6y agoMany questionable Russian sites do full port scans not only on localhost but on all the private subnets. I had to block all access to ports above 1024 for all local subnets. Usually people don't have firewall rules for that.
- gfxgirl 6y agoYes, a drive by web page shouldn't be able to do this but similarly a native app shouldn't be able to do this and yet I suspect some not insignificant percent of native apps, especially on mobile on both OSes are doing this either directly, the app dev is doing it deliberately, or via one of the many 3rd party libraries they included but aren't aware of the behavior. I really want the OS to prevent this by default and require permission from the user. I want apps (probably only possible on iOS/Android) to have to list the sites they'll connect to, that list will have to be reasonably small 10-30 sites with special exceptions for browsers This would have 2 positive affects. #1 it would prevent the apps from scanning the network. #2 it would effectively force apps to launch the user's browser for external links instead of an embedded browser in which they can spy on all activity.
- ilikenwf 6y agoThis slideshow by an NSA dude seems to go into this, from 2016. https://datatracker.ietf.org/meeting/96/materials/slides-96-saag-1/ https://datatracker.ietf.org/meeting/96/materials/slides-96-...
- dreamcompiler 6y agoDamn. Yet another example of "This is why we can't have nice things."
- mirimir 6y agoPlease ELI5 why it doesn't happen for www.ebay.com using Firefox in Debian. I see no websocket connections to localhost in Network Monitor or iftop.
- snikch 6y agoDid they check the source of the request? My guess would have been an extension doing this instead of the site.
- franga2000 6y agoAllowing ws connections to local addresses can be pretty useful in many cases (admittedly, many of these could be better solved with WebExtensions' native messaging) so disallowing it would not fly. But since this is pretty rare, a message saying: "this website is trying to connect to services running on your computer - allow/deny?" would be pretty easy to implement and solve this for good. Sites that need this already require you to jump through hoops, so one more popup would be fine, but sites that do this for other reasons would probably not want to risk a popup.
- problem_halting 6y agoI see the port scanning behavior in Firefox and Chrome but not in Brave, even with Brave shields down. Anyone else use Brave?