Live data from Hacker News

I'm being cyberattacked by Tesla, Inc

dreamstation.systems

61–70 of 127 posts

Re: I'm being cyberattacked by Tesla, Inc

#61

Earlier quoted context omitted.

Wouldn't the same apply to pool.ntp.org then? Maybe running a web server on the same IP as an NTP server is a bad idea.

a .tesla.com certificate might well enable more shenanigans than a .pool.ntp.org cert.

Hope there are no sensitive *.tesla.com cookies out there...

Re: I'm being cyberattacked by Tesla, Inc

#62
I just checked my own webserver logs (I also run a sever in the ntp pool) and I too see some hits in my webserver logs.

They look to all be log4j vuln scanning activity (CVE-2021-44228), and the volume isn't that high (a few a day, and not every day). They just have some overzealous vuln scanning. And yes, they shouldn't have the NTP pool under their DNS name.

I've had all sorts of strange things happen because of my ntp pool membership, this one is pretty far on the benign end of things.

Re: I'm being cyberattacked by Tesla, Inc

#65
post #58

I'd try to contact Assetnote. Most (sadly not all) managed vuln scan companies are pretty sensitive to scanning stuff that doesn't belong to their client and could expose them to liabilities because they don't have permission.

Yeah, I'll try to do this, but I can't find anything better than the generic contact form.

Re: I'm being cyberattacked by Tesla, Inc

#66

> it has received ~8,000 requests from two of your scanning hosts If it were 8000 requests per second , this might be worthy of some investigation. But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.

It's not 8000 requests. It's 8000 attempts to exploit various software on OP's server.

is this not something you can report to the FBI or something? is trying to hack someone servers not illegal?

Re: I'm being cyberattacked by Tesla, Inc

#67

> it has received ~8,000 requests from two of your scanning hosts If it were 8000 requests per second , this might be worthy of some investigation. But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.

Isn't this technically a crime, since they're actively attempting to access a computer system they don't own?

yup just report them to the FBI

Re: I'm being cyberattacked by Tesla, Inc

#68

Earlier quoted context omitted.

a .tesla.com certificate might well enable more shenanigans than a .pool.ntp.org cert.

Hope there are no sensitive *.tesla.com cookies out there...

The chance of being issued a certificate in this instance, while theoretically possible, is infinitesimally small.

Re: I'm being cyberattacked by Tesla, Inc

#69

I've been consistently attacked by ShadowServer who have the following sponsors, Akamai, APNIC Foundation, Arctic Security, AusCERT, Avast, Backblaze, Canadian Center for Cyber Security, CERT.AT, CERT.br, CERT.LV, CIRA, CIRCL, Craig Newmark Philanthropies, CSIRT.LI, CSIS Security Group, DFN‑CSIRT, Digital Trust Center, EURid, HelseCERT, ICANN, Identity Digital, KPN, Mastercard, NASK (CERT.pl), NCSC Ireland, NICS, Nih…

Calling vuln scanning from a non-profit a felony is a bit of a stretch. Many for-profit companies do similar vuln scanning and then threaten companies with security "scorecards". That is borderline extortion.

Re: I'm being cyberattacked by Tesla, Inc

#70
50,000 requests in the span of ... 21 days? It might be interesting if it were 50 million in those 21 days (even then, 27 RPS is ... nothing). Drop a report to AWS T&S, block, drop, reject, and move on. This is like less than background noise at this point.

Edit: tamping down a bit of my prickliness because it looks like this individual is a relative newcomer to running internet-facing services. This is actually a pretty good intro to that: the place as a whole is a cesspool and any conceivable “attack”, scan, probe, pentest is, has, or will be happening at all times. Some you can mitigate yourself, others you’ll need to bring in a specialist service (see DDoS sinks and mitigation services, for example) or contact someone’s abuse address, others you just have to ignore because it’s just not directed at you personally, or just not worth more than three seconds’ thought beyond a firewall rule. This is the latter. Maybe interesting if this is the first time you’re seeing something like this, but for more grizzled operators like myself, it doesn’t even register as notable anymore.

Post reply on HN