Earlier quoted context omitted.
One solution is to not set up and run a computer program that relies on bad information to perform automated cyber-attacks on third parties.
How do you suggest I determine the information is bad, if the domain is hosted on tesla.com, and Tesla says I am authorized to test it? Should I inspect all 1,368 subdomains on tesla.com by hand, and then do the same for 400+ bug bounty programs?
I'm being cyberattacked by Tesla, Inc
91–100 of 127 posts
Re: I'm being cyberattacked by Tesla, Inc
#92Earlier quoted context omitted.
How do you suggest I determine the information is bad, if the domain is hosted on tesla.com, and Tesla says I am authorized to test it? Should I inspect all 1,368 subdomains on tesla.com by hand, and then do the same for 400+ bug bounty programs?
Yes, unless you think that trying to do a bug bounty is a good excuse to participate in DoS.
Re: I'm being cyberattacked by Tesla, Inc
#93Earlier quoted context omitted.
Yes. I have personally done this before, the correct sequence of moves is: 1. Call your neighbor, ask for permission. 2. Check the door 3. Lock the door If you don’t have their phone number, you are not on good enough terms to touch their lock.
This is why the checking doors / neighborhood analogy isn't a good one. Having one person with poor computer security negatively impacts everyone. Hacked sites turn into phishing landing pages, exploit kit hosting, stolen data dumps, and launching off points for attacks on everyone else. The vuln scanning ShadowServer is doing is meant to be a public good, which is why they share the info with ISPs and governments. S…
And even if you remove the analogy, ShadowServer means good, but good intentions doesn’t necessarily make their action moral or legal.
Yes, compromised servers can be used by hackers as means to commit crimes. But when these groups scan the entire internet, they do cause harm as well, as shown in the original linked article. Much less harm than a black hat, but they still waste time and resources from innocent third parties.
It’s fair to ask if the harm they cause is worth the good they do.
Re: I'm being cyberattacked by Tesla, Inc
#94I would assume the fastest way to actually make this stop would be to setup a bunch of honeypot exploits, trigger their detection and someone will figure out what they did wrong. Other than not, with these huge companies you have 0 recourse.
"Hey Texas Model S #345 just left KXYZ, moving at >100mph towards the pad. Everyone get cameras out!"
It'll be gone by lunchtime that day.
Re: I'm being cyberattacked by Tesla, Inc
#95Earlier quoted context omitted.
Yes, unless you think that trying to do a bug bounty is a good excuse to participate in DoS.
The OP says they have received 50,000 requests in about a month. What service is being denied by 0.01 requests per second?
Re: I'm being cyberattacked by Tesla, Inc
#96Earlier quoted context omitted.
The OP says they have received 50,000 requests in about a month. What service is being denied by 0.01 requests per second?
You're now confident that the other 399+ domains you mentioned are not under any sort of duress because they're controlled by people who are away of what's happening?
Re: I'm being cyberattacked by Tesla, Inc
#97I understand that Tesla is treating your NTP server, a volunteer server and part of the greater volunteer pool of NTP servers, as their own infrastructure.
However, I can't tell from the article if the scans originate with:
A.) IT staff at Tesla that are scanning exposed services on what they perceive, or claim wrongly, as their own network for vulnerabilities.
B.) Somehow a rogue operator (read botnet)
C.) A rogue operator who is using the cars themselves to run exploit scans?
C would be the most alarming and concerning.
Re: I'm being cyberattacked by Tesla, Inc
#98Earlier quoted context omitted.
You're now confident that the other 399+ domains you mentioned are not under any sort of duress because they're controlled by people who are away of what's happening?
I feel confident that no system exposed to the internet should have a problem with 50,000 requests per month! If they do, they probably shouldn't run a public NTP server, or have a public IP address at all.
Re: I'm being cyberattacked by Tesla, Inc
#99I’m pretty sure this way they’ve hardcoded the NTPs is actually against the ToS for use of the NTP pool too. The way a vendor embedding NTP is _meant_ to do so is documented here: https://www.ntppool.org/en/vendors.html On another note, back when I ran a web hosting business we hosted a few NTP servers in the pool. It’s such a simple thing to give back, and worth anyone who can make a stable contribution doing so.
When was this page last updated? I would expect that number to be in the hundreds of millions these days, perhaps even billions.
Re: I'm being cyberattacked by Tesla, Inc
#100Earlier quoted context omitted.
I feel confident that no system exposed to the internet should have a problem with 50,000 requests per month! If they do, they probably shouldn't run a public NTP server, or have a public IP address at all.
Okay, so you're just confident in exactly how many requests everyone else in the world will be making if you try to pentest resources unbeknownst to their owners.
I think this line of reasoning doesn't make any sense. The internet is not an inherently safe network regardless of what we wish for; we can't wish away the bad activity, and it's only going to increase. The activity that helps prevent the bad activity from working is a net positive.