Live data from Hacker News

I'm being cyberattacked by Tesla, Inc

dreamstation.systems

111–120 of 127 posts

Re: I'm being cyberattacked by Tesla, Inc

#111

Earlier quoted context omitted.

How do you suggest I determine the information is bad, if the domain is hosted on tesla.com, and Tesla says I am authorized to test it? Should I inspect all 1,368 subdomains on tesla.com by hand, and then do the same for 400+ bug bounty programs?

When I engage a security assessor on behalf of a client, I am required to provide detailed scope and attest to in scope assets (including IP blocks and public hostnames), as well as that I have legal authority for them to be tested. This is validated by my executive sponsor. It is your responsibility to do your due diligence as a security researcher versus “spray and pray” to ensure you are not exceeding the scope be…

I reckon there's a decent argument to be made that an authorization to scan *.tesla.com definitively does NOT extend to any hosts resolved via a CNAME chain that goes foo.tesla.com -> bah.not-tesla.com -> host-that-never-authorized-attacking.

Re: I'm being cyberattacked by Tesla, Inc

#112

As a bug bounty researcher, my systems would do the same thing if they ended up georouted to this IP. *.tesla.com is marked as in scope on https://bugcrowd.com/engagements/tesla , and my agents will probe anything under there as it is presumed to have explicit authorization. Not sure if there is a great solution, but I'm inclined to say that attack traffic like this is the new normal. In fact, the attack volume they…

I'm curious about your use of agents for security bug bounties. Do you use self hosted models? GLM 5.2? Do the economics of self-hosting make it worth it? Or if you use 3rd party hosted models, don't you run into safeguards that try to prevent hacking? (unless convincing them it's a genuine ethical bug bounty program works, but it doesn't in my experience)

Re: I'm being cyberattacked by Tesla, Inc

#113
post #107
post #6

Remember in 2003 when netgear hardcoded a university's NTP server into a ton of their products? Well.... https://www.google.com/search?&q=university+ntp+server+netge... https://pages.cs.wisc.edu/~plonka/netgear-sntp/

[flagged]

> erm... @ downvotes

> Hijacking the highest ranking comment

Gee, I wonder why...

Re: I'm being cyberattacked by Tesla, Inc

#114
post #93

Earlier quoted context omitted.

This is why the checking doors / neighborhood analogy isn't a good one. Having one person with poor computer security negatively impacts everyone. Hacked sites turn into phishing landing pages, exploit kit hosting, stolen data dumps, and launching off points for attacks on everyone else. The vuln scanning ShadowServer is doing is meant to be a public good, which is why they share the info with ISPs and governments. S…

It is a good analogy because thieves stealing from one house successfully gives them resources and incentivizes them stealing from the same area again. And even if you remove the analogy, ShadowServer means good, but good intentions doesn’t necessarily make their action moral or legal. Yes, compromised servers can be used by hackers as means to commit crimes. But when these groups scan the entire internet, they do ca…

> It’s fair to ask if the harm they cause is worth the good they do.

Researcher disclosures, even with POCs, have moved the industry to action incumbents would have rather buried. I’m thinking of CPU and memory exploits, and stuff like log4j, as examples.

Frontier AI is enabling the cyber arms race more than anything past, and certainly more than some bot slowly crawling web servers for old vulnerabilities.

If we’re talking harm, it should be in the broader context of internet history, imo.

Re: I'm being cyberattacked by Tesla, Inc

#115
post #78

Earlier quoted context omitted.

I did something like this a few weeks ago on my photography site: https://robertmay.photography/journal/meta-has-tried-to-scra... Meta not only hasn't noticed, but is currently sending about 11 requests per second to my site. I've also seemingly trapped one of those TV proxy scraper nets as I'm getting absolutely hammered by requests from all over the place now. I get maybe 10 legit visitors per day, and I'm currentl…

Return a HTTP 301 pointing to https://facebook.com ? Might make them scan themselves instead.

Most distributed bots won't follow a 301. If 404/400 don't work, just 444 them, they're not worth giving back a response, especially on a personal website.

Re: I'm being cyberattacked by Tesla, Inc

#117

Earlier quoted context omitted.

When I engage a security assessor on behalf of a client, I am required to provide detailed scope and attest to in scope assets (including IP blocks and public hostnames), as well as that I have legal authority for them to be tested. This is validated by my executive sponsor. It is your responsibility to do your due diligence as a security researcher versus “spray and pray” to ensure you are not exceeding the scope be…

I reckon there's a decent argument to be made that an authorization to scan *.tesla.com definitively does NOT extend to any hosts resolved via a CNAME chain that goes foo.tesla.com -> bah.not-tesla.com -> host-that-never-authorized-attacking.

Pretty hard to implement in practice!

% dig www.tesla.com +short

www.tesla.com.edgekey.net.

e1792.dscx.akamaiedge.net.

Re: I'm being cyberattacked by Tesla, Inc

#119
post #80

Earlier quoted context omitted.

In today’s world, a crime is only a crime if you get charged. Tesla has enough power to not get charged.

Tesla isn’t doing the scanning though, instead somebody thinks they are scanning Tesla, but Tesla points them to someone else. The scanner is likely illegal. The pointing is… so stupid nobody thought to make a law about it.

Ask a lawyer about sending an unpleasant letter to the scanner, detailing the situation and demanding that they cease & desist. That clobbers their "we didn't know" defense, and their Legal Dept. will likely order them to stop ASAP.

Re: I'm being cyberattacked by Tesla, Inc

#120
post #6

Remember in 2003 when netgear hardcoded a university's NTP server into a ton of their products? Well.... https://www.google.com/search?&q=university+ntp+server+netge... https://pages.cs.wisc.edu/~plonka/netgear-sntp/

Would have been fun if the NTP server would return dates in the futures for requests from Netgear equipment, making certificates invalid and giving people an awful experience.
Post reply on HN