Remix.run Logo
londons_explore 4 hours ago

> it has received ~8,000 requests from two of your scanning hosts

If it were 8000 requests per second, this might be worthy of some investigation.

But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.

walrus01 4 hours ago | parent | next [-]

Please read the article, it's not the volume of the NTP requests, they're actively sending exploit/attempt to compromise payloads. They're probing things in a way that you would ordinarily only do to your own internal infrastructure.

"They tried all kinds of exploits against me: path traversal, webshell uploads, probing software internals, probing WordPress and other CMS management endpoints, SSRF, Log4Shell, and a lot more."

hackernudes 4 hours ago | parent [-]

If you host a webserver on the internet it is normal to receive that kind of traffic all the time. Source: I host a server on my Comcast connection.

lukan 4 hours ago | parent | next [-]

But it shouldn't be normal, that a car company tries to automatically hack private servers.

walrus01 4 hours ago | parent | prev | next [-]

I don't disagree with you, I have tons of things that have public interfaces (as mundane as a fully patched wordpress where the wp-admin login is accessible to external blog writers), we get tens of thousands of random shit anything per day. But the problem here is that Tesla is treating NTP pool operators like they are their internal infrastructure. Also because the attribution of the 'attacks' is fairly well known.

I don't go complaining on the internet about the absolute shitflood of compromised routers on broadband ISPs in Indonesia probing my stuff 24x7x365 because I know it would be futile. But if I found one specific american company that was repeatedly probing my stuff all the time? Maybe I'd escalate it.

robinpie 4 hours ago | parent | prev [-]

Oh absolutely, I just think the specific nature of this (legitimate commercial vuln scanner thinks I'm Tesla) is funny

robinpie 4 hours ago | parent | prev | next [-]

It's HTTP requests, not NTP requests, and the volume isn't the problem, it's that Assetnote is sending live exploit payloads /at all/ to a stranger on Tesla's behalf

iamjackg 4 hours ago | parent | prev | next [-]

Isn't this technically a crime, since they're actively attempting to access a computer system they don't own?

emkoemko 3 hours ago | parent | next [-]

yup just report them to the FBI

iAMkenough 3 hours ago | parent | prev [-]

In today’s world, a crime is only a crime if you get charged. Tesla has enough power to not get charged.

FabCH 3 hours ago | parent [-]

Tesla isn’t doing the scanning though, instead somebody thinks they are scanning Tesla, but Tesla points them to someone else.

The scanner is likely illegal.

The pointing is… so stupid nobody thought to make a law about it.

SadTrombone 4 hours ago | parent | prev [-]

It's not 8000 requests. It's 8000 attempts to exploit various software on OP's server.

emkoemko 3 hours ago | parent [-]

is this not something you can report to the FBI or something? is trying to hack someone servers not illegal?