Is WPS浏览器助手:文档在线阅读编辑 safe?
WPS浏览器助手 is medium risk. Visiting any page triggers a page-view event to a Kingsoft analytics service with URL, title, and referrer, firing all session since content scripts cover <all_urls>. Reporting ships on by default, encrypted on the wire. Opt-out in Options.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Page URL, Title and Referrer Sent to Kingsoft Analytics on Every Site
Visiting any page triggers a page-view event to a Kingsoft analytics service with URL, title, and referrer, firing all session since content scripts cover <all_urls>.
Reporting ships on by default, encrypted on the wire.
Opt-out in Options.
You navigate to any web page, any site, anywhere.
The extension records the visit and sends the page URL, its title, and the page you came from to a Kingsoft analytics service.
No interaction with a WPS document is required. The reporting is on by default and runs on every site because the extension's content scripts and host access cover <all_urls>.
| Field | Value | Why it matters | |
|---|---|---|---|
The page URL you are visiting | https://en.wikipedia.org/wiki/Encryption | The exact page you are on, including any tracking or identifying parameters in the address. | |
The page title | Encryption - Wikipedia | The title of the page you are viewing, which often describes the content. | |
The page you came from (referrer) | https://www.google.com/search?q=encryption | Where you were before this page, builds a chain of where you have been. |
On the wire each event body is encrypted, so you cannot read it in your browser's network inspector. Decrypting a captured request with the key shipped inside the extension reveals the page-view contents.
{
"name": "_page_view",
"title": "Encryption - Wikipedia",
"url": "https://en.wikipedia.org/wiki/Encryption",
"refer": "https://www.google.com/search?q=encryption",
"_encrypted_fields": "title,url,refer"
}The code that builds and labels the page-view event, from the extension's shipping source.
// Analytics reporter config
Reporter.defaults = {
dynamicUrl: 'https://dw-online.ksosoft.com',
sendUrl: 'https://shuc-js.ksord.com/bat/js/cors'
};
Reporter.use(transport, {
aesKey: 'ZctYg7JjXcPySXxw', // 16-byte AES-128 key, shipped in the extension
rsaKey: '8762DEC3...'
});// Built on navigation; carries the page you are on.
const event = new DWEvent('_page_view', {
...common,
...defaults._page_view,
title: page.getTitle(), // current page title
url: page.getUrl(), // current page URL
refer: page.getReferer() // the page you came from
});// These three fields are encrypted before the body is sent.
if (event.name === '_page_view') {
encryptedFields = ['title', 'url', 'refer'];
}Decrypts captured DW Reporter event bodies using the AES-128-CBC key shipped in the extension, revealing the page-view url/title/refer fields.
#!/usr/bin/env node
// Decrypts WPS browser helper DW Reporter analytics bodies.
// rn.Reporter.use(transport, { aesKey: 'ZctYg7JjXcPySXxw' })
// key = UTF8('ZctYg7JjXcPySXxw') -> 16 bytes -> AES-128
// iv = CryptoJS.enc.Utf8.parse('') -> 16 zero bytes
// mode = CBC (CryptoJS default), padding = Pkcs7, wire = base64
const crypto = require('crypto');
const fs = require('fs');
const KEY = Buffer.from('ZctYg7JjXcPySXxw', 'utf8'); // 16 bytes -> AES-128
const IV = Buffer.alloc(16, 0); // zero IV
function decrypt(b64) {
const ct = Buffer.from(b64, 'base64');
const d = crypto.createDecipheriv('aes-128-cbc', KEY, IV);
d.setAutoPadding(true); // Pkcs7
return Buffer.concat([d.update(ct), d.final()]).toString('utf8');
}
const rows = JSON.parse(fs.readFileSync(process.argv[2] || 'bodies.json', 'utf8'));
let ok = 0;
for (const r of rows) {
try {
console.log(`\n=== ${r.id} (${r.source}) ===`);
console.log(decrypt(r.body));
ok++;
} catch (e) {
console.log(`\n=== ${r.id} DECRYPT FAILED: ${e.message} ===`);
}
}
console.log(`\nDecrypted ${ok}/${rows.length} bodies.`);
- 1Save captured request bodies to bodies.json as [{"id":"...","source":"...","body":"<base64>"}].
- 2Run: node decrypt.js bodies.json.
- 3Read the decrypted _page_view envelopes.
- shuc-js.ksord.com
Receives the encrypted page-view event bodies (DW Reporter sendUrl, /bat/js/cors). Operated by Kingsoft.
- dw-online.ksosoft.com
DW Reporter dynamic-config endpoint (dynamicUrl). Kingsoft analytics domain.
What it can do
Permissions this extension asks for, as declared in version 4.1.6. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Read and change your data on every site you visit
<all_urls>
See every page you navigate to, as you navigate to it
webNavigation
Watch every request your browser makes
webRequest
Start, monitor and manage your downloads
downloads
Store data in your browser
storage
See the address and title of every tab you have open
tabs
Read and change cookies, including the ones that keep you signed in
cookies
Talk to a program installed on your computer, outside the browser's sandbox
nativeMessaging
Block and redirect the requests your browser makes
declarativeNetRequest
Receive push messages from its developer's servers
gcm
Add items to the right-click menu
contextMenus
Show a panel beside the page
sidePanel