example.com/path/to/article
000 points · username · 0 hours ago
example.com458 points · 119 comments · 8 days ago · robinpie
walrus01
simonjgreen
The way a vendor embedding NTP is _meant_ to do so is documented here: https://www.ntppool.org/en/vendors.html
On another note, back when I ran a web hosting business we hosted a few NTP servers in the pool. It’s such a simple thing to give back, and worth anyone who can make a stable contribution doing so.
darwinlee
kittikitti
Akamai, APNIC Foundation, Arctic Security, AusCERT, Avast, Backblaze, Canadian Center for Cyber Security, CERT.AT, CERT.br, CERT.LV, CIRA, CIRCL, Craig Newmark Philanthropies, CSIRT.LI, CSIS Security Group, DFN‑CSIRT, Digital Trust Center, EURid, HelseCERT, ICANN, Identity Digital, KPN, Mastercard, NASK (CERT.pl), NCSC Ireland, NICS, Nihon Cyber Defence, Nucleus Security, Orange Polska, Precursor Security, Protect.ngo, Public Interest Registry (PIR), Red Hat, SURFcert, SWITCH, Team Cymru, Trend Micro, Trivest AG, Tucows, Verisign, VulnCheck,
I don't care what they say they're doing, I hate how corporations can act with impunity with these types of things while everyone else would get a felony for it.
buzer
kjs3
graypegg
Tangential, but I love the design of your blog. That's so freakishly accurate to old GNOME 2 Ubuntu, amazing work.
motbus3
andai
richwater
Other than not, with these huge companies you have 0 recourse.
iancarroll
Not sure if there is a great solution, but I'm inclined to say that attack traffic like this is the new normal. In fact, the attack volume they got is quite small compared to the volume I have seen on other tech company subdomains - the new normal is probably much worse.
bmenrigh
They look to all be log4j vuln scanning activity (CVE-2021-44228), and the volume isn't that high (a few a day, and not every day). They just have some overzealous vuln scanning. And yes, they shouldn't have the NTP pool under their DNS name.
I've had all sorts of strange things happen because of my ntp pool membership, this one is pretty far on the benign end of things.
emkoemko
fred_is_fred
larodi
KaiserPro
ChrisMarshallNY
As opposed to intentionally being a nuisance?
VladVladikoff
rg -zFI pool-ntp.tesla.com access.log*
Neat! Didn’t know about this command that’s very helpful
matt3210
sroussey
consensus1
[deleted]
NotWhatUThink
They tried all kinds of exploits against me ... probing WordPress and other CMS management endpoints
This is standard bot crawler traffic. Anyone who runs a home server sees attempts to load wp paths all the time
theideaofcoffee
Edit: tamping down a bit of my prickliness because it looks like this individual is a relative newcomer to running internet-facing services. This is actually a pretty good intro to that: the place as a whole is a cesspool and any conceivable “attack”, scan, probe, pentest is, has, or will be happening at all times. Some you can mitigate yourself, others you’ll need to bring in a specialist service (see DDoS sinks and mitigation services, for example) or contact someone’s abuse address, others you just have to ignore because it’s just not directed at you personally, or just not worth more than three seconds’ thought beyond a firewall rule. This is the latter. Maybe interesting if this is the first time you’re seeing something like this, but for more grizzled operators like myself, it doesn’t even register as notable anymore.
sippingabonedry
This happens EVERY day to EVERY web server out there. I have a personal site that gets thousands of requests per day from bots.
Running a public server (like NTP) means you will get tons of strange requests. Moreso if you run a web server on the same IP because bots will scrape certificate transparency logs. The entire IPv4 space is scanned continuously.
This may sound harsh, but you cannot stop it. It is whack-a-mole. Filter it and move on, go outside and touch grass, seriously. This is not worth being upset over.
I treat these as an opportunity to tune my filters and firewall rules.
caaqil
gmmachine
I understand that Tesla is treating your NTP server, a volunteer server and part of the greater volunteer pool of NTP servers, as their own infrastructure.
However, I can't tell from the article if the scans originate with:
A.) IT staff at Tesla that are scanning exposed services on what they perceive, or claim wrongly, as their own network for vulnerabilities.
B.) Somehow a rogue operator (read botnet)
C.) A rogue operator who is using the cars themselves to run exploit scans?
C would be the most alarming and concerning.
tekla
Speculation: Assetnote pulled in everything it could find under tesla.com, including pool-ntp.tesla.com, which CNAMEs to pool.ntp.org, which can resolve to my machine — 67.215.249.229. The asset inventory saves this as a Tesla asset, and starts throwing exploits at me, a stranger.
Not a vuln in Tesla, and I'm not asking for anything, but I just wanted to let you know that you may unintentionally be being a nuisance.
londons_explore
it has received ~8,000 requests from two of your scanning hosts
If it were 8000 requests per second, this might be worthy of some investigation.
But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.
https://www.google.com/search?&q=university+ntp+server+netge...
https://pages.cs.wisc.edu/~plonka/netgear-sntp/