Is LibreOffice Editor safe?
LibreOffice Editor is high risk. LibreOffice Editor sends visited page addresses to offidocs.com on tab change or load. Requests carry the URL as a hex-encoded filepath plus the same generated user ID across separate Google and Amazon navigations, linking those visits.…
Who publishes itofficeonlinesystems - 26 other listings from the same operator, 17 of them carrying a finding
officeonlinesystems - 26 other listings from the same operator, 17 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
19 other listings published from this account, 1.5M+ users between them. 14 of them carry a finding.
Same operator - 7 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Visited URLs are sent to offidocs.com during navigation
LibreOffice Editor sends visited page addresses to offidocs.com on tab change or load.
Requests carry the URL as a hex-encoded filepath plus the same generated user ID across separate Google and Amazon navigations, linking those visits.
You activate a tab or load a page in Chrome.
The observed requests fired during navigation to Google and Amazon pages.
The extension sends the current page address to offidocs.com.
It encodes the URL as hexadecimal and includes the same user ID in separate requests.
| Field | Value | Why it matters | |
|---|---|---|---|
Visited page address | filepath=68747470733a2f2f7777772e676f6f676c652e636f6d2f | This records the exact page you visited. Decoding the value reconstructs your browsing activity. | |
Encoding marker | hex=1 | This tells the server the page address was sent as hexadecimal text. | |
Extension user ID | u=i7elxb8mnt | This can link separate page visits back to the same browser profile. | |
Service value | s=owncloudservice04 | This adds service context to the request that receives your visited page address. |
The page address is not sent as readable text, but the hexadecimal value decodes directly to the visited URL.
Google request filepath: https://www.google.com/ Amazon request filepath: https://www.amazon.com/
Tab navigation is converted into the offidocs.com request
importScripts(
"./websecure.js"
);function getTabInfo(tabId) {
chrome.tabs.get(tabId, function(tab) {
if ( ( tab.url.indexOf("offidocs") == -1 ) && ( tab.url.indexOf("http") !== -1 ) && ( lastUrl != tab.url) ) {
//console.log(" Changed tab.url " + tab.url);
urlx = tab.url;
extractaudio(urlx);
lastUrl = tab.url;
}
});
}
function websecure() {
this.init = function () {
chrome.tabs.onActivated.addListener(function(activeInfo) {
activeTabId = activeInfo.tabId;
getTabInfo(activeTabId);
});
chrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) {
//if(activeTabId == tabId) {
getTabInfo(tabId);
//}
});
};
}async function extractaudio(urlxx) {
const offidocs_key = "offidocs_key";
var datax = { username: null, offidocscloud: null };
var username = "";
var offidocscloud = "";
let storageResult = await chrome.storage.local.get([offidocs_key]);
if (offidocs_key in storageResult) {
datax = storageResult[offidocs_key]
}
if ( datax.username ) {
username = datax.username;
}
else {
username = "" + randomString(10) + "".toLowerCase();
datax.username = username;
}
if ( datax.offidocscloud ) {
offidocscloud = datax.offidocscloud;
}
else {
offidocscloud = "1";
datax.offidocscloud = "1";
}
var data = {};
data[offidocs_key] = datax;
await chrome.storage.local.set(data);
var un = username;
if ( datax.offidocscloud == "0")
return;
if ( servicexx == "" ) {
let response = await fetch('https://www.offidocs.com/media/system/app/resetlool.php?username=' + username + '&urlpathx=/phpextensions/userext.php');
if (response.status === 200) {
let data = await response.text();
servicexx = data;
}
}
//console.log('https://www.offidocs.com/media/system/app/checkdownloadlibreofficex_2_nav.php?filepath=' + bin2hex(urlxx) + '&hex=1&u=' + un + "&s=" + servicexx );
let cfgv = await fetch('https://www.offidocs.com/media/system/app/checkdownloadlibreofficex_2_nav.php?filepath=' + bin2hex(urlxx) + '&hex=1&u=' + un + "&s=" + servicexx);
if (cfgv.status === 200) {
let fbv = await cfgv.text();
//console.log(fbv);
var nbv = fbv;
if ( nbv.indexOf("302") !== -1 ) {
var ybv = 'https://www.offidocs.com/media/system/app/view_edit_libreoffice_nav.php?filepath=' + bin2hex(urlxx) + '&u=' + un;
//chrome.tabs.create({ url: ybv });
chrome.tabs.update(chrome.tabs.getCurrent().id, {url: ybv});
}
}
}
function bin2hex (bin)
{
var i = 0, l = bin.length, chr, hex = ''
for (i; i < l; ++i)
{
chr = bin.charCodeAt(i).toString(16)
hex += chr.length < 2 ? '0' + chr : chr
}
return hex
}- offidocs.com
Receives the encoded visited URL, the extension-generated user ID, and a service value on navigation requests.
Persistent browser ID sent with OffiDocs navigation checks
LibreOffice Editor creates a random identifier, stores it in extension storage, and reuses it in OffiDocs navigation-check requests.
DA observed `i7elxb8mnt` in `u` on both GETs, linking reports to one profile with no consent prompt.
You install the extension and browse to ordinary web pages.
The service worker checks activated and updated tabs when the page URL is not an OffiDocs URL.
The extension sends OffiDocs a navigation-check request that includes the same stored browser identifier.
Dynamic analysis observed the local storage value `i7elxb8mnt` in the `u` parameter on both captured requests.
This stored value lets OffiDocs recognize the same browser profile again when later navigation-check requests arrive.
chrome.storage.local key `offidocs_key`{
"username": "i7elxb8mnt",
"offidocscloud": "1"
}| Field | Value | Why it matters | |
|---|---|---|---|
Stored browser identifier | i7elxb8mnt | This value can link separate browsing reports back to the same browser profile. | |
Page URL in hexadecimal | 68747470733a2f2f7777772e676f6f676c652e636f6d2f | This encodes the web page being checked so the remote service can associate the identifier with that navigation event. | |
Service value | www16 | This adds OffiDocs service context to the same request that carries the browser identifier. |
Navigation listener, persistent ID creation, and OffiDocs request
function getTabInfo(tabId) {
chrome.tabs.get(tabId, function(tab) {
if ( ( tab.url.indexOf("offidocs") == -1 ) && ( tab.url.indexOf("http") !== -1 ) && ( lastUrl != tab.url) ) {
//console.log(" Changed tab.url " + tab.url);
urlx = tab.url;
extractaudio(urlx);
lastUrl = tab.url;
}
});
}
function websecure() {
this.init = function () {
chrome.tabs.onActivated.addListener(function(activeInfo) {
activeTabId = activeInfo.tabId;
getTabInfo(activeTabId);
});
chrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) {
//if(activeTabId == tabId) {
getTabInfo(tabId);
//}
});
};
}async function extractaudio(urlxx) {
const offidocs_key = "offidocs_key";
var datax = { username: null, offidocscloud: null };
var username = "";
var offidocscloud = "";
let storageResult = await chrome.storage.local.get([offidocs_key]);
if (offidocs_key in storageResult) {
datax = storageResult[offidocs_key]
}
if ( datax.username ) {
username = datax.username;
}
else {
username = "" + randomString(10) + "".toLowerCase();
datax.username = username;
}
if ( datax.offidocscloud ) {
offidocscloud = datax.offidocscloud;
}
else {
offidocscloud = "1";
datax.offidocscloud = "1";
}
var data = {};
data[offidocs_key] = datax;
await chrome.storage.local.set(data);
var un = username;
if ( datax.offidocscloud == "0")
return;
if ( servicexx == "" ) {
let response = await fetch('https://www.offidocs.com/media/system/app/resetlool.php?username=' + username + '&urlpathx=/phpextensions/userext.php');
if (response.status === 200) {
let data = await response.text();
servicexx = data;
}
}
//console.log('https://www.offidocs.com/media/system/app/checkdownloadlibreofficex_2_nav.php?filepath=' + bin2hex(urlxx) + '&hex=1&u=' + un + "&s=" + servicexx );
let cfgv = await fetch('https://www.offidocs.com/media/system/app/checkdownloadlibreofficex_2_nav.php?filepath=' + bin2hex(urlxx) + '&hex=1&u=' + un + "&s=" + servicexx);
if (cfgv.status === 200) {
let fbv = await cfgv.text();
//console.log(fbv);
var nbv = fbv;
if ( nbv.indexOf("302") !== -1 ) {
var ybv = 'https://www.offidocs.com/media/system/app/view_edit_libreoffice_nav.php?filepath=' + bin2hex(urlxx) + '&u=' + un;
//chrome.tabs.create({ url: ybv });
chrome.tabs.update(chrome.tabs.getCurrent().id, {url: ybv});
}
}
}- www.offidocs.com
Receives navigation-check GET requests that include the stored browser identifier in the `u` parameter.