3 ms·
> it has received ~8,000 requests from two of your scanning hosts If it were 8000 requests per second, this might be worthy of some investigation. But 8000 nt
by londons_explore 20d ago
> it has received ~8,000 requests from two of your scanning hosts
If it were 8000 requests per second, this might be worthy of some investigation.
But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.
- walrus01 20d agoPlease read the article, it's not the volume of the NTP requests, they're actively sending exploit/attempt to compromise payloads. They're probing things in a way that you would ordinarily only do to your own internal infrastructure. "They tried all kinds of exploits against me: path traversal, webshell uploads, probing software internals, probing WordPress and other CMS management endpoints, SSRF, Log4Shell, and a lot more."
- hackernudes 20d agoIf you host a webserver on the internet it is normal to receive that kind of traffic all the time. Source: I host a server on my Comcast connection.
- robinpie 20d agoOh absolutely, I just think the specific nature of this (legitimate commercial vuln scanner thinks I'm Tesla) is funny
- walrus01 20d agoI don't disagree with you, I have tons of things that have public interfaces (as mundane as a fully patched wordpress where the wp-admin login is accessible to external blog writers), we get tens of thousands of random shit anything per day. But the problem here is that Tesla is treating NTP pool operators like they are their internal infrastructure. Also because the attribution of the 'attacks' is fairly well known. I don't go complaining on the internet about the absolute shitflood of compromised routers on broadband ISPs in Indonesia probing my stuff 24x7x365 because I know it would be futile. But if I found one specific american company that was repeatedly probing my stuff all the time? Maybe I'd escalate it.
- lukan 20d agoBut it shouldn't be normal, that a car company tries to automatically hack private servers.
- wpm 19d agoThis is HN plenty of us host servers at home and understand the obviously true fact that you can't really stop it forever. But that obviously isn't what we're talking about here. We're talking about a massive multibillion dollar corporation breaking the rules of a community project they joined by committing a Jr Sysadmin grade fuck up and ghosting the people who's infrastructure they have now placed in the crosshairs of serious, enterprise grade automated vulnerability testing from a company who might now inadvertently be committing a felony. That's a bit different than getting a few dozen lazy hits a day because some botnet got to your IP in the Shodan and saw the Plex port open.
- robinpie 20d agoIt's HTTP requests, not NTP requests, and the volume isn't the problem, it's that Assetnote is sending live exploit payloads /at all/ to a stranger on Tesla's behalf
- SadTrombone 20d agoIt's not 8000 requests. It's 8000 attempts to exploit various software on OP's server.
- emkoemko 20d agois this not something you can report to the FBI or something? is trying to hack someone servers not illegal?
- iamjackg 20d agoIsn't this technically a crime, since they're actively attempting to access a computer system they don't own?
- iAMkenough 20d agoIn today’s world, a crime is only a crime if you get charged. Tesla has enough power to not get charged.
- FabCH 20d agoTesla isn’t doing the scanning though, instead somebody thinks they are scanning Tesla, but Tesla points them to someone else. The scanner is likely illegal. The pointing is… so stupid nobody thought to make a law about it.
- bell-cot 20d agoAsk a lawyer about sending an unpleasant letter to the scanner, detailing the situation and demanding that they cease & desist. That clobbers their "we didn't know" defense, and their Legal Dept. will likely order them to stop ASAP.
- emkoemko 20d agoyup just report them to the FBI