Live data from Hacker News

I'm being cyberattacked by Tesla, Inc

dreamstation.systems

11–20 of 127 posts

Re: I'm being cyberattacked by Tesla, Inc

#11

> it has received ~8,000 requests from two of your scanning hosts If it were 8000 requests per second , this might be worthy of some investigation. But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.

Please read the article, it's not the volume of the NTP requests, they're actively sending exploit/attempt to compromise payloads. They're probing things in a way that you would ordinarily only do to your own internal infrastructure.

"They tried all kinds of exploits against me: path traversal, webshell uploads, probing software internals, probing WordPress and other CMS management endpoints, SSRF, Log4Shell, and a lot more."

Re: I'm being cyberattacked by Tesla, Inc

#13
I’m pretty sure this way they’ve hardcoded the NTPs is actually against the ToS for use of the NTP pool too.

The way a vendor embedding NTP is _meant_ to do so is documented here: https://www.ntppool.org/en/vendors.html

On another note, back when I ran a web hosting business we hosted a few NTP servers in the pool. It’s such a simple thing to give back, and worth anyone who can make a stable contribution doing so.

Re: I'm being cyberattacked by Tesla, Inc

#14

> it has received ~8,000 requests from two of your scanning hosts If it were 8000 requests per second , this might be worthy of some investigation. But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.

It's HTTP requests, not NTP requests, and the volume isn't the problem, it's that Assetnote is sending live exploit payloads /at all/ to a stranger on Tesla's behalf

Re: I'm being cyberattacked by Tesla, Inc

#15

> it has received ~8,000 requests from two of your scanning hosts If it were 8000 requests per second , this might be worthy of some investigation. But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.

It's not 8000 requests. It's 8000 attempts to exploit various software on OP's server.

Re: I'm being cyberattacked by Tesla, Inc

#16

I’m pretty sure this way they’ve hardcoded the NTPs is actually against the ToS for use of the NTP pool too. The way a vendor embedding NTP is _meant_ to do so is documented here: https://www.ntppool.org/en/vendors.html On another note, back when I ran a web hosting business we hosted a few NTP servers in the pool. It’s such a simple thing to give back, and worth anyone who can make a stable contribution doing so.

Yes, they should absolutely be using a vendor zone instead of a CNAME under tesla.com.

Re: I'm being cyberattacked by Tesla, Inc

#18
Thankfully it doesn't seem to be much traffic, but still... weird. You'd hope at somepoint the weird responses would get looked at in some log, but I won't hold my breath for that haha.

Tangential, but I love the design of your blog. That's so freakishly accurate to old GNOME 2 Ubuntu, amazing work.

Post reply on HN