Websites Conducting Port Scans
Websites Conducting Port Scans : Security researcher Charlie Belmer is reporting that commercial websites such as eBay are conducting port scans of their visitors. Looking at the list of ports they are scanning, they are looking for VNC services being run on the host, which is the same thing that was reported for bank sites. I marked out the ports and what they are known for (with a few blanks for ones I am unfamiliar with): 5900: VNC 5901: VNC port 2 5902: VNC port 3 5903: VNC port 4 5279: 3389: Windows remote desktop / RDP 5931: Ammy Admin remote desktop 5939: 5944: 5950: WinVNC 6039: X window system 6040: X window system 63333: TrippLite power alert UPS 7070: RealAudio No one seems to know why : I could not believe my eyes, but it was quickly reproduced by me (see below for my observation). I surfed around to several sites, and found one more that does this (the citibank site, see below for my observation) I further see, at least across ebay.com and citi...