216 points robinpie 1 hour ago 52 comments
fred_is_fred 47 minutes ago | parent
nullpoint420 37 minutes ago | parent
ameliaquining 16 minutes ago | parent
richwater 47 minutes ago | parent
Other than not, with these huge companies you have 0 recourse.
robinpie 46 minutes ago | parent
adzm 43 minutes ago | parent
Joel_Mckay 10 minutes ago | parent
slau 43 minutes ago | parent
Once the asset scanner detects the vulns, everyone will kick into high gear to patch this.
robotmay 19 minutes ago | parent
Meta not only hasn't noticed, but is currently sending about 11 requests per second to my site. I've also seemingly trapped one of those TV proxy scraper nets as I'm getting absolutely hammered by requests from all over the place now. I get maybe 10 legit visitors per day, and I'm currently blocking 406,787 IPs from things that have fallen into my honeypot.
I've tweaked my site to return empty status responses a configurable amount of time but the traffic has been so intense that Traefik is now struggling, so I'm going to have to figure out something else. I was returning over-capacity errors and I think that was a mistake, I've swapped to 400 range status codes now. I don't want to use Cloudflare so I'm not sure what to do after this.
The people at these companies are either incompetent or malicious.
Joel_Mckay 15 minutes ago | parent
One's best bet is to play possum, and use your clients last login IPs falling in your service area geo-IP ranges for a firewall white-list. Then redirect the other traffic for a black hole route.
If the nuisance hosts assume they have driven the host offline, they will eventually give up and move on. =3
tekla 46 minutes ago | parent
> Speculation: Assetnote pulled in everything it could find under tesla.com, including pool-ntp.tesla.com, which CNAMEs to pool.ntp.org, which can resolve to my machine — 67.215.249.229. The asset inventory saves this as a Tesla asset, and starts throwing exploits at me, a stranger.
> Not a vuln in Tesla, and I'm not asking for anything, but I just wanted to let you know that you may unintentionally be being a nuisance.
walrus01 46 minutes ago | parent
https://www.google.com/search?&q=university+ntp+server+netge...
VladVladikoff 46 minutes ago | parent
Neat! Didn’t know about this command that’s very helpful
londons_explore 44 minutes ago | parent
If it were 8000 requests per second, this might be worthy of some investigation.
But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.
walrus01 41 minutes ago | parent
"They tried all kinds of exploits against me: path traversal, webshell uploads, probing software internals, probing WordPress and other CMS management endpoints, SSRF, Log4Shell, and a lot more."
hackernudes 35 minutes ago | parent
robinpie 34 minutes ago | parent
walrus01 26 minutes ago | parent
I don't go complaining on the internet about the absolute shitflood of compromised routers on broadband ISPs in Indonesia probing my stuff 24x7x365 because I know it would be futile. But if I found one specific american company that was repeatedly probing my stuff all the time? Maybe I'd escalate it.
lukan 25 minutes ago | parent
robinpie 40 minutes ago | parent
SadTrombone 40 minutes ago | parent
NotWhatUThink 41 minutes ago | parent
This is standard bot crawler traffic. Anyone who runs a home server sees attempts to load wp paths all the time
robinpie 33 minutes ago | parent
simonjgreen 40 minutes ago | parent
The way a vendor embedding NTP is _meant_ to do so is documented here: https://www.ntppool.org/en/vendors.html
On another note, back when I ran a web hosting business we hosted a few NTP servers in the pool. It’s such a simple thing to give back, and worth anyone who can make a stable contribution doing so.
robinpie 39 minutes ago | parent
jameshilliard 33 minutes ago | parent
Note that in the past I've had companies writing embedded linux based firmware using ntppool for time sync request their own vendor zones, however a lot of those requests were ignored so it's unclear if that's still expected. In the end they ended up just using the default ntppool domains since they never got their own vendor zones.
Aurornis 9 minutes ago | parent
buzer 39 minutes ago | parent
robinpie 35 minutes ago | parent
ratorx 26 minutes ago | parent
sippingabonedry 24 minutes ago | parent
Maybe running a web server on the same IP as an NTP server is a bad idea.
Polizeiposaune 19 minutes ago | parent
sippingabonedry 15 minutes ago | parent
Hell, they issue certificates to IP addresses now. For cloud systems, ownership of an IP could be a few hours.
This has almost certainly been deemed an acceptable risk.
graypegg 38 minutes ago | parent
Tangential, but I love the design of your blog. That's so freakishly accurate to old GNOME 2 Ubuntu, amazing work.
andai 36 minutes ago | parent
sippingabonedry 31 minutes ago | parent
This happens EVERY day to EVERY web server out there. I have a personal site that gets thousands of requests per day from bots.
Running a public server (like NTP) means you will get tons of strange requests. Moreso if you run a web server on the same IP because bots will scrape certificate transparency logs. The entire IPv4 space is scanned continuously.
This may sound harsh, but you cannot stop it. It is whack-a-mole. Filter it and move on, go outside and touch grass, seriously. This is not worth being upset over.
I treat these as an opportunity to tune my filters and firewall rules.
robinpie 23 minutes ago | parent
sippingabonedry 18 minutes ago | parent
Tesla is a large enterprise.
They almost certainly subscribe to some overpriced SaaS garbage which is manned by offshore drones who by definition do not care because they're not paid enough to care.
Unfortunately this isn't the 80s anymore where you can ring up a system administrator at a university and get a human on the other end.
That said: cool looking website btw.
MBCook 19 minutes ago | parent
sippingabonedry 11 minutes ago | parent
No, I do not.
I get thousands of these "security scanner" requests on a low-traffic site weekly if not daily.
I would have added the IP addresses to my firewall's Io blacklist and forgotten about it the next day. It's really all you can do.
consensus1 21 minutes ago | parent
darwinlee 19 minutes ago | parent
caaqil 14 minutes ago | parent