5 ms·
As a bug bounty researcher, my systems would do the same thing if they ended up georouted to this IP. *.tesla.com is marked as in scope on https://bugcrowd.com/
by iancarroll 19d ago
As a bug bounty researcher, my systems would do the same thing if they ended up georouted to this IP. *.tesla.com is marked as in scope on https://bugcrowd.com/engagements/tesla https://bugcrowd.com/engagements/tesla, and my agents will probe anything under there as it is presumed to have explicit authorization.
Not sure if there is a great solution, but I'm inclined to say that attack traffic like this is the new normal. In fact, the attack volume they got is quite small compared to the volume I have seen on other tech company subdomains - the new normal is probably much worse.
- deleted 19d ago[deleted]
- xmodem 19d agoOne solution is to not set up and run a computer program that relies on bad information to perform automated cyber-attacks on third parties.
- iancarroll 19d agoHow do you suggest I determine the information is bad, if the domain is hosted on tesla.com, and Tesla says I am authorized to test it? Should I inspect all 1,368 subdomains on tesla.com by hand, and then do the same for 400+ bug bounty programs?
- natebc 19d ago[dead]
- saghm 19d agoYes, unless you think that trying to do a bug bounty is a good excuse to participate in DoS.
- iancarroll 19d agoThe OP says they have received 50,000 requests in about a month. What service is being denied by 0.01 requests per second?
- saghm 19d agoYou're now confident that the other 399+ domains you mentioned are not under any sort of duress because they're controlled by people who are away of what's happening?
- iancarroll 19d agoI feel confident that no system exposed to the internet should have a problem with 50,000 requests per month! If they do, they probably shouldn't run a public NTP server, or have a public IP address at all.
- saghm 19d agoOkay, so you're just confident in exactly how many requests everyone else in the world will be making if you try to pentest resources unbeknownst to their owners.
- iancarroll 19d agoAre you confident you are not viewing too many pages on HN? What if many other people are also trying to read this thread? I think this line of reasoning doesn't make any sense. The internet is not an inherently safe network regardless of what we wish for; we can't wish away the bad activity, and it's only going to increase. The activity that helps prevent the bad activity from working is a net positive.
- saghm 19d ago> Are you confident you are not viewing too many pages on HN? What if many other people are also trying to read this thread? I think it's pretty disingenuous to compare viewing a couple of pages once a day with running scripting tools against over 400 websites. > I think this line of reasoning doesn't make any sense. The internet is not an inherently safe network regardless of what we wish for; we can't wish away the bad activity, and it's only going to increase. The activity that helps prevent the bad activity from working is a net positive. Oh good, no one has ever claimed "it's for your own good" when doing something selfish without consent.
- xmodem 19d agoMaybe i'm old fashioned, but personally I think the onus should be on the person sending out unauthorized malicious requests to figure out how to not do that. Any responsible bug bounty researcher reviewing the DNS zone by hand would spot the CNAME and remove it from the target list. You don't get to wash your hands of that because your chatbot did it.
- iancarroll 19d agoEven before AI, I can't imagine a single bug bounty researcher doing that. Pre-AI, everyone ran a tool like subfinder to enumerate subdomains, httpx to resolve them, nuclei to scan them, etc. There's no human review involved there at the subdomain level. And I don't know anyone that would really look at the intermediary of a CNAME even during a manual test. Maybe if it was obviously a third party service.
- toomuchtodo 19d agoWhen I engage a security assessor on behalf of a client, I am required to provide detailed scope and attest to in scope assets (including IP blocks and public hostnames), as well as that I have legal authority for them to be tested. This is validated by my executive sponsor. It is your responsibility to do your due diligence as a security researcher versus “spray and pray” to ensure you are not exceeding the scope beyond your intended target. Dump the subdomains, resolve them, and review where they resolve to in order to understand the footprint and attack surface boundaries before engaging scanning or agentic red team harnesses. Automate as much as possible for building the state graph of the target, but a human must remain in the loop to sanity check. To not do this means you could be attacking hyperscaler object storage, a CDN, a partner SaaS frontend, ticketing systems, mail systems, etc (ie anything someone may CNAME off the root domain but that is outside of their organization’s control).
- bigiain 19d agoI reckon there's a decent argument to be made that an authorization to scan *.tesla.com definitively does NOT extend to any hosts resolved via a CNAME chain that goes foo.tesla.com -> bah.not-tesla.com -> host-that-never-authorized-attacking.
- iancarroll 19d agoPretty hard to implement in practice! % dig www.tesla.com +short www.tesla.com.edgekey.net. e1792.dscx.akamaiedge.net. <akamai IP>
- varenc 19d agoI'm curious about your use of agents for security bug bounties. Do you use self hosted models? GLM 5.2? Do the economics of self-hosting make it worth it? Or if you use 3rd party hosted models, don't you run into safeguards that try to prevent hacking? (unless convincing them it's a genuine ethical bug bounty program works, but it doesn't in my experience)
- iancarroll 18d agoI think most people are using some variation of Chinese models due to the safeguards. I have some self hosting but the economics are bad - OpenRouter etc are a very competitive marketplace and usually better.