- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎04-28-2018 08:17 PM
Some, but not all, items suddenly now have a link with "See full item description" in the description area which opens a new window to a 'vi.vipr.ebaydesc.com' address... I've never seen this before... Googling and searching these forums suggests that it's been around in the past though, and sometimes associated with malware?
Can anyone tell me why it would just start showing up for me now, why eBay allows putting descriptions in these off-page links, and whether they've solved the issue of malware hiding in them? And is ebaydesc.com owned by eBay, or is it outside their control?
I'd love to read a full description of what's going on and why, instead of just the bits and pieces I've found so far.
Anyone?
Solved! Go to Best Answer
Accepted Solutions
"See full item description" link, opens window to a vi.vipr.ebaydesc.com address? Malware or no?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎04-28-2018 09:23 PM
ANYTHING can be involved in malware /malicious events, but in this case not so. 'vi.vipr.ebaydesc.com' is a legitimate eBay.domain, and where listing description content is served from.
In Firefox browsers you can right click on the meat of the description text (below item specifics) in any listing and choose 'This frame>View Source'. A source code view for that description body should open and will be served from vi.vipr.ebaydesc.com (shown in the source code dialog title bar). Perfectly legitimate.
As far as I know, eBay has not solved some potential issues with malicious content when offsite links are used. A while back I looked into another buyers issues with fake auctions using probably hjacked accounts where the miscreants were using offsite links to force the "See full item description button" , which would open to an offsite webpage, and then vector the sale offsite from there. I speculated that they COULD have done malicious things at that point (even though they appeared not to be doing so). Not sure what eBAy could do anyway, other than a blanket ban on offsite links which would break a lot of legitimate functionality (Youtube and other videos, mfg site info, images, etc.)
"See full item description" link, opens window to a vi.vipr.ebaydesc.com address? Malware or no?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎04-28-2018 08:30 PM
No.
Just one of their 'better ideas'.
Forget keeping up with the Joneses. Be the Finklegrubers!
OK kids, time to get the Dodge loaded up again. I hear 'Poppy's By the Tree' calling. This trip might be a long one too.
"See full item description" link, opens window to a vi.vipr.ebaydesc.com address? Malware or no?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎04-28-2018 08:35 PM
Appreciate the reply, but not sure what it means exactly.
I would have thought, with past reports from some users that their antivirus was flagging it, that eBay would have a dedicated explainer page somewhere by now.
Should I just avoid ever clicking that "see full item description" link? And what's the risk if I already did?
"See full item description" link, opens window to a vi.vipr.ebaydesc.com address? Malware or no?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎04-28-2018 08:55 PM
https://community.ebay.com/t5/Replacing-Active-Content/bd-p/activecontent
Forget keeping up with the Joneses. Be the Finklegrubers!
OK kids, time to get the Dodge loaded up again. I hear 'Poppy's By the Tree' calling. This trip might be a long one too.
"See full item description" link, opens window to a vi.vipr.ebaydesc.com address? Malware or no?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎04-28-2018 09:19 PM - edited ‎04-28-2018 09:20 PM
Thanks!
So it sounds, from the first post in that list, near the end of it, that it has to do with unsecure (non-https) content being in the user's description, which newer browsers don't allow on eBay's otherwise-https item pages:
"... eBay's solution (to prevent the new browsers from blocking display of the description) will be to open the description in a separate window, the way it currently handles mobile viewing. Descriptions with secure content, on the other hand, would continue to display within the main page."
Strange that I just started seeing that today, but it sounds like not a malware issue, even if unsecure (unencrypted). It sounds like the phishing attempts were in the past, someone had hacked the ebaydesc.com site, and that was unrelated to this current issue of the workarounds for new browsers?
"See full item description" link, opens window to a vi.vipr.ebaydesc.com address? Malware or no?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎04-28-2018 09:23 PM
ANYTHING can be involved in malware /malicious events, but in this case not so. 'vi.vipr.ebaydesc.com' is a legitimate eBay.domain, and where listing description content is served from.
In Firefox browsers you can right click on the meat of the description text (below item specifics) in any listing and choose 'This frame>View Source'. A source code view for that description body should open and will be served from vi.vipr.ebaydesc.com (shown in the source code dialog title bar). Perfectly legitimate.
As far as I know, eBay has not solved some potential issues with malicious content when offsite links are used. A while back I looked into another buyers issues with fake auctions using probably hjacked accounts where the miscreants were using offsite links to force the "See full item description button" , which would open to an offsite webpage, and then vector the sale offsite from there. I speculated that they COULD have done malicious things at that point (even though they appeared not to be doing so). Not sure what eBAy could do anyway, other than a blanket ban on offsite links which would break a lot of legitimate functionality (Youtube and other videos, mfg site info, images, etc.)
"See full item description" link, opens window to a vi.vipr.ebaydesc.com address? Malware or no?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎04-28-2018 09:32 PM
Thanks much, that helps. I still think this is important enough and common enough that eBay should have an info page (outside this forum) that describes all aspects of it in full in their own words, so there's no need for users to try to fill each other in by pointing to other posts.
What you say is true: someone could now fake the "see full description" link, and have it take you to a malware site instead. So I guess it's safest to check where those are going first before clicking. Which now makes me wonder too if eBay runs all links through malware-detection software before they're allowed to go "live" on the site.
"See full item description" link, opens window to a vi.vipr.ebaydesc.com address? Malware or no?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎04-29-2018 03:13 PM
@cheerindigo wrote:What you say is true: someone could now fake the "see full description" link, and have it take you to a malware site instead. So I guess it's safest to check where those are going first before clicking. Which now makes me wonder too if eBay runs all links through malware-detection software before they're allowed to go "live" on the site.
1) You can pay attention to where the "see full description" link is located in the listing. It will always be in eBay's "box", never in the actual description area. If you ever see that button in the wrong place, it will be fake. Note the outlined box around the button in my test listing, as that is where eBay's button belongs:
https://www.ebay.com/itm/This-is-a-test-please-do-not-bid/380647614391
2) eBay does not follow every link for malware. Instead, eBay has a "links" policy forbidding offsite links except to specifically allowed (white-listed) domains for videos and freight.
https://www.ebay.com/help/Policy/-/Links_policy?id=4248
eBay is currently filtering listing links for whether they point to an eBay domain, a whitelist domain, or to an unauthorized destination.
Sellers whose listings still contain the unauthorized "weblinks" are sent regular notices to remove the links and eBay will eventually block those listings from renewing. Additionally, eBay has indicated that such pages will be demoted in search or may not appear at all until the links are removed.
I don't know what timeline eBay has for actually blocking listings with "weblinks" as they are currently in the notification period that allows sellers time to clean up their pages. When eBay rolls out full enforcement, we should see an end to most of the fraudulent links.
