Earlier quoted context omitted.
How do you suggest I determine the information is bad, if the domain is hosted on tesla.com, and Tesla says I am authorized to test it? Should I inspect all 1,368 subdomains on tesla.com by hand, and then do the same for 400+ bug bounty programs?
When I engage a security assessor on behalf of a client, I am required to provide detailed scope and attest to in scope assets (including IP blocks and public hostnames), as well as that I have legal authority for them to be tested. This is validated by my executive sponsor. It is your responsibility to do your due diligence as a security researcher versus “spray and pray” to ensure you are not exceeding the scope be…
I'm being cyberattacked by Tesla, Inc
111–120 of 127 posts
Re: I'm being cyberattacked by Tesla, Inc
#112As a bug bounty researcher, my systems would do the same thing if they ended up georouted to this IP. *.tesla.com is marked as in scope on https://bugcrowd.com/engagements/tesla , and my agents will probe anything under there as it is presumed to have explicit authorization. Not sure if there is a great solution, but I'm inclined to say that attack traffic like this is the new normal. In fact, the attack volume they…
Re: I'm being cyberattacked by Tesla, Inc
#113Remember in 2003 when netgear hardcoded a university's NTP server into a ton of their products? Well.... https://www.google.com/search?&q=university+ntp+server+netge... https://pages.cs.wisc.edu/~plonka/netgear-sntp/
[flagged]
> Hijacking the highest ranking comment
Gee, I wonder why...
Re: I'm being cyberattacked by Tesla, Inc
#114Earlier quoted context omitted.
This is why the checking doors / neighborhood analogy isn't a good one. Having one person with poor computer security negatively impacts everyone. Hacked sites turn into phishing landing pages, exploit kit hosting, stolen data dumps, and launching off points for attacks on everyone else. The vuln scanning ShadowServer is doing is meant to be a public good, which is why they share the info with ISPs and governments. S…
It is a good analogy because thieves stealing from one house successfully gives them resources and incentivizes them stealing from the same area again. And even if you remove the analogy, ShadowServer means good, but good intentions doesn’t necessarily make their action moral or legal. Yes, compromised servers can be used by hackers as means to commit crimes. But when these groups scan the entire internet, they do ca…
Researcher disclosures, even with POCs, have moved the industry to action incumbents would have rather buried. I’m thinking of CPU and memory exploits, and stuff like log4j, as examples.
Frontier AI is enabling the cyber arms race more than anything past, and certainly more than some bot slowly crawling web servers for old vulnerabilities.
If we’re talking harm, it should be in the broader context of internet history, imo.
Re: I'm being cyberattacked by Tesla, Inc
#115Earlier quoted context omitted.
I did something like this a few weeks ago on my photography site: https://robertmay.photography/journal/meta-has-tried-to-scra... Meta not only hasn't noticed, but is currently sending about 11 requests per second to my site. I've also seemingly trapped one of those TV proxy scraper nets as I'm getting absolutely hammered by requests from all over the place now. I get maybe 10 legit visitors per day, and I'm currentl…
Return a HTTP 301 pointing to https://facebook.com ? Might make them scan themselves instead.
Re: I'm being cyberattacked by Tesla, Inc
#116“You must absolutely not use the default pool.ntp.org zone names as the default configuration in your application or appliance.” ref: https://www.ntppool.org/en/vendors.html
Re: I'm being cyberattacked by Tesla, Inc
#117Earlier quoted context omitted.
When I engage a security assessor on behalf of a client, I am required to provide detailed scope and attest to in scope assets (including IP blocks and public hostnames), as well as that I have legal authority for them to be tested. This is validated by my executive sponsor. It is your responsibility to do your due diligence as a security researcher versus “spray and pray” to ensure you are not exceeding the scope be…
I reckon there's a decent argument to be made that an authorization to scan *.tesla.com definitively does NOT extend to any hosts resolved via a CNAME chain that goes foo.tesla.com -> bah.not-tesla.com -> host-that-never-authorized-attacking.
% dig www.tesla.com +short
www.tesla.com.edgekey.net.
e1792.dscx.akamaiedge.net.
Re: I'm being cyberattacked by Tesla, Inc
#118Re: I'm being cyberattacked by Tesla, Inc
#119Earlier quoted context omitted.
In today’s world, a crime is only a crime if you get charged. Tesla has enough power to not get charged.
Tesla isn’t doing the scanning though, instead somebody thinks they are scanning Tesla, but Tesla points them to someone else. The scanner is likely illegal. The pointing is… so stupid nobody thought to make a law about it.
Re: I'm being cyberattacked by Tesla, Inc
#120Remember in 2003 when netgear hardcoded a university's NTP server into a ton of their products? Well.... https://www.google.com/search?&q=university+ntp+server+netge... https://pages.cs.wisc.edu/~plonka/netgear-sntp/