5 ms·
> it has received ~8,000 requests from two of your scanning hosts If it were 8000 requests per second, this might be worthy of some investigation. But 8000 nt
by londons_explore 3d ago
> it has received ~8,000 requests from two of your scanning hosts
If it were 8000 requests per second, this might be worthy of some investigation.
But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.
- SadTrombone 3d agoIt's not 8000 requests. It's 8000 attempts to exploit various software on OP's server.
- emkoemko 3d agois this not something you can report to the FBI or something? is trying to hack someone servers not illegal?
- robinpie 3d agoIt's HTTP requests, not NTP requests, and the volume isn't the problem, it's that Assetnote is sending live exploit payloads /at all/ to a stranger on Tesla's behalf
- walrus01 3d agoPlease read the article, it's not the volume of the NTP requests, they're actively sending exploit/attempt to compromise payloads. They're probing things in a way that you would ordinarily only do to your own internal infrastructure. "They tried all kinds of exploits against me: path traversal, webshell uploads, probing software internals, probing WordPress and other CMS management endpoints, SSRF, Log4Shell, and a lot more."
- hackernudes 3d agoIf you host a webserver on the internet it is normal to receive that kind of traffic all the time. Source: I host a server on my Comcast connection.
- robinpie 3d agoOh absolutely, I just think the specific nature of this (legitimate commercial vuln scanner thinks I'm Tesla) is funny
- walrus01 3d agoI don't disagree with you, I have tons of things that have public interfaces (as mundane as a fully patched wordpress where the wp-admin login is accessible to external blog writers), we get tens of thousands of random shit anything per day. But the problem here is that Tesla is treating NTP pool operators like they are their internal infrastructure. Also because the attribution of the 'attacks' is fairly well known. I don't go complaining on the internet about the absolute shitflood of compromised routers on broadband ISPs in Indonesia probing my stuff 24x7x365 because I know it would be futile. But if I found one specific american company that was repeatedly probing my stuff all the time? Maybe I'd escalate it.
- lukan 3d agoBut it shouldn't be normal, that a car company tries to automatically hack private servers.
- iamjackg 3d agoIsn't this technically a crime, since they're actively attempting to access a computer system they don't own?
- iAMkenough 3d agoIn today’s world, a crime is only a crime if you get charged. Tesla has enough power to not get charged.
- FabCH 3d agoTesla isn’t doing the scanning though, instead somebody thinks they are scanning Tesla, but Tesla points them to someone else. The scanner is likely illegal. The pointing is… so stupid nobody thought to make a law about it.
- emkoemko 3d agoyup just report them to the FBI