Earlier quoted context omitted.
Wouldn't the same apply to pool.ntp.org then? Maybe running a web server on the same IP as an NTP server is a bad idea.
a .tesla.com certificate might well enable more shenanigans than a .pool.ntp.org cert.
I'm being cyberattacked by Tesla, Inc
61–70 of 127 posts
Re: I'm being cyberattacked by Tesla, Inc
#62They look to all be log4j vuln scanning activity (CVE-2021-44228), and the volume isn't that high (a few a day, and not every day). They just have some overzealous vuln scanning. And yes, they shouldn't have the NTP pool under their DNS name.
I've had all sorts of strange things happen because of my ntp pool membership, this one is pretty far on the benign end of things.
Re: I'm being cyberattacked by Tesla, Inc
#63As opposed to intentionally being a nuisance?
Re: I'm being cyberattacked by Tesla, Inc
#64Re: I'm being cyberattacked by Tesla, Inc
#65I'd try to contact Assetnote. Most (sadly not all) managed vuln scan companies are pretty sensitive to scanning stuff that doesn't belong to their client and could expose them to liabilities because they don't have permission.
Re: I'm being cyberattacked by Tesla, Inc
#66> it has received ~8,000 requests from two of your scanning hosts If it were 8000 requests per second , this might be worthy of some investigation. But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.
It's not 8000 requests. It's 8000 attempts to exploit various software on OP's server.
Re: I'm being cyberattacked by Tesla, Inc
#67> it has received ~8,000 requests from two of your scanning hosts If it were 8000 requests per second , this might be worthy of some investigation. But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.
Isn't this technically a crime, since they're actively attempting to access a computer system they don't own?
Re: I'm being cyberattacked by Tesla, Inc
#68Earlier quoted context omitted.
a .tesla.com certificate might well enable more shenanigans than a .pool.ntp.org cert.
Hope there are no sensitive *.tesla.com cookies out there...
Re: I'm being cyberattacked by Tesla, Inc
#69I've been consistently attacked by ShadowServer who have the following sponsors, Akamai, APNIC Foundation, Arctic Security, AusCERT, Avast, Backblaze, Canadian Center for Cyber Security, CERT.AT, CERT.br, CERT.LV, CIRA, CIRCL, Craig Newmark Philanthropies, CSIRT.LI, CSIS Security Group, DFN‑CSIRT, Digital Trust Center, EURid, HelseCERT, ICANN, Identity Digital, KPN, Mastercard, NASK (CERT.pl), NCSC Ireland, NICS, Nih…
Re: I'm being cyberattacked by Tesla, Inc
#70Edit: tamping down a bit of my prickliness because it looks like this individual is a relative newcomer to running internet-facing services. This is actually a pretty good intro to that: the place as a whole is a cesspool and any conceivable “attack”, scan, probe, pentest is, has, or will be happening at all times. Some you can mitigate yourself, others you’ll need to bring in a specialist service (see DDoS sinks and mitigation services, for example) or contact someone’s abuse address, others you just have to ignore because it’s just not directed at you personally, or just not worth more than three seconds’ thought beyond a firewall rule. This is the latter. Maybe interesting if this is the first time you’re seeing something like this, but for more grizzled operators like myself, it doesn’t even register as notable anymore.