# My server is being included in what seems to be bungled internal Tesla vulnerability scanning

**URL:** <https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672>\
**Category:** Server operators\
**Created:** [September 8, 2026, 12:57pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672 "2026-09-08T12:57:08Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![robinpie](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/robinpie/32/2670_2.png) [@robinpie](https://community.ntppool.org/u/robinpie)\
**Post date:** [September 8, 2026, 12:57pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/1 "2026-09-08T12:57:08Z")

</div>

Over roughly the past two days, my HTTP server (that happens to be on the same IP as my NTP server) has received ~8,000 requests from 54.165.75.96 and 35.168.63.24, UA Assetnote/1.0.0 (ExposureScan), with many templated exploit payloads. Every payload used [pool-ntp.tesla.com](http://pool-ntp.tesla.com) as the target hostname. I assume their asset inventory accidentally included that subdomain which does not actually point to Tesla assets.

I have emailed Tesla about this and am not concerned about it (I’m patched against everything they tried and I have no reason to believe this wasn’t an innocent accident). However I am curious if anyone else is seeing this, or if they resolved it to my IP once and kept hitting it.

---

<div class="post-metadata">

**Author:** ![avij](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/avij/32/197_2.png) [@avij](https://community.ntppool.org/u/avij)\
**Post date:** [September 8, 2026, 5:46pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/2 "2026-09-08T17:46:32Z")

</div>

For the record, pool-ntp.tesla.com is a CNAME to pool.ntp.org.

I’m not seeing such requests in my logs.

---

<div class="post-metadata">

**Author:** ![Bas](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/bas/32/465_2.png) [@Bas](https://community.ntppool.org/u/Bas)\
**Post date:** [September 8, 2026, 5:51pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/3 "2026-09-08T17:51:08Z")

</div>

It’s a spammer, as it referred to something else before.  
Not the pool.  
It’s bullshit.

---

<div class="post-metadata">

**Author:** ![robinpie](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/robinpie/32/2670_2.png) [@robinpie](https://community.ntppool.org/u/robinpie)\
**Post date:** [September 8, 2026, 7:02pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/4 "2026-09-08T19:02:59Z")

</div>

Yeah I’m aware of that, which is why the mistake on their part regarding accidentally including it in their list of assets to scan is obvious

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/mnordhoff/32/1470_2.png) [@mnordhoff](https://community.ntppool.org/u/mnordhoff)\
**Post date:** [September 9, 2026, 1:43am UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/5 "2026-09-09T01:43:41Z")

</div>

At least one of my US NTP Pool servers got it:

```auto
$ sudo rg -zFI pool-ntp.tesla.com access.log* | awk '{print $1}' | sort | uniq -c | sort -gr | head
   9126 54.165.75.96
   7461 35.168.63.24
   6123 52.44.200.251
     11 64.227.103.50
      6 146.190.142.16
      4 3.101.230.148
      3 3.88.188.142
      3 3.101.216.68
      2 54.213.2.72
      2 54.202.10.40

```

(Is there a better way to do that? There is probably a better way to do that.)

The 3 big IPs have “ExposureScan” in the user-agent for most of the requests. It’s been happening since at least 2026-08-15 (UTC).

Also got a handful of miscellaneous abuse/scan requests to that hostname from a couple dozen other IPs.

---

<div class="post-metadata">

**Author:** ![Bas](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/bas/32/465_2.png) [@Bas](https://community.ntppool.org/u/Bas)\
**Post date:** [September 9, 2026, 4:34pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/6 "2026-09-09T16:34:19Z")

</div>

Link goes to here… [https://www.galsys.eu/](https://www.galsys.eu/)

It’s spam.

---

<div class="post-metadata">

**Author:** ![grifferz](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/grifferz/32/74_2.png) [@grifferz](https://community.ntppool.org/u/grifferz)\
**Post date:** [September 9, 2026, 4:51pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/7 "2026-09-09T16:51:12Z")

</div>

_Which_ link?

If you’re talking about the pool-ntp tesla hostname, you understand that it’s a CNAME that points to the NTP pool, right? So if you visit it in a web browser you may see any web site that a random pool volunteer has running on their IP address.

If that’s not what you mean, can you elaborate? It’s very confusing to just keep thoring out these “it’s spam” “bullshit” responses.

---

<div class="post-metadata">

**Author:** ![Bas](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/bas/32/465_2.png) [@Bas](https://community.ntppool.org/u/Bas)\
**Post date:** [September 9, 2026, 5:31pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/8 "2026-09-09T17:31:58Z")

</div>

No it refers to the website is gave, all the time.

---

<div class="post-metadata">

**Author:** ![grifferz](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/grifferz/32/74_2.png) [@grifferz](https://community.ntppool.org/u/grifferz)\
**Post date:** [September 9, 2026, 6:05pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/9 "2026-09-09T18:05:20Z")

</div>

Can you please explain what you are talking about? _What_ web site that _who_ gave?

```auto
$ host pool-ntp.tesla.com
pool-ntp.tesla.com is an alias for pool.ntp.org.
pool.ntp.org has address 212.71.233.40
pool.ntp.org has address 85.199.214.102
pool.ntp.org has address 94.15.142.187
pool.ntp.org has address 212.132.222.19
pool.ntp.org mail is handled by 0

```

---

<div class="post-metadata">

**Author:** ![avij](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/avij/32/197_2.png) [@avij](https://community.ntppool.org/u/avij)\
**Post date:** [September 9, 2026, 6:36pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/10 "2026-09-09T18:36:53Z")

</div>

In addition to the responses by grifferz above:

$ host www.galsys.eu  
www.galsys.eu has address 172.233.59.169  
www.galsys.eu has IPv6 address 2600:3c0e::f03c:94ff:fe24:f6a2

[https://www.ntppool.org/scores/172.233.59.169](https://www.ntppool.org/scores/172.233.59.169)  
[https://www.ntppool.org/scores/2600:3c0e::f03c:94ff:fe24:f6a2](https://www.ntppool.org/scores/2600:3c0e::f03c:94ff:fe24:f6a2)

This means the server Bas ran into is a legit NTP pool server that also happens to host a website. This is very common. [https://www.ntppool.org/en/join.html](https://www.ntppool.org/en/join.html) says “… but sometimes people type pool.ntp.org and are then surprised to get a random web page” which is exactly what Bas is seeing here. In short, nothing to see here, move on. Next message in this topic better be about someone else seeing those scans in their logs, or something else that is relevant to the scanning. Let’s stop the spam thread here.

---

<div class="post-metadata">

**Author:** ![robinpie](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/robinpie/32/2670_2.png) [@robinpie](https://community.ntppool.org/u/robinpie)\
**Post date:** [September 9, 2026, 9:06pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/11 "2026-09-09T21:06:06Z")

</div>

Thanks lol. This thread is so frustrating.

To restate more succintly: [pool-ntp.tesla.com](http://pool-ntp.tesla.com) CNAMEs to [pool.ntp.org](http://pool.ntp.org). This is normal and fine. But it looks like that some Tesla automated scanner rolled my IP from it and is trying to exploit it. I can tell, because among their attacks, are attacks over HTTP, which include Host headers. Is anyone else seeing this?

---

<div class="post-metadata">

**Author:** ![Bas](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/bas/32/465_2.png) [@Bas](https://community.ntppool.org/u/Bas)\
**Post date:** [September 10, 2026, 2:29pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/12 "2026-09-10T14:29:55Z")

</div>

> [@robinpie](#):
>
> But it looks like that some Tesla automated scanner rolled my IP from it and is trying to exploit it.

I would repport it to @ask so he can take action against that pool.  
As typical company-pools have their own servers, at least I would expect them to have their own.

---

<div class="post-metadata">

**Author:** ![grifferz](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/grifferz/32/74_2.png) [@grifferz](https://community.ntppool.org/u/grifferz)\
**Post date:** [September 10, 2026, 2:49pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/13 "2026-09-10T14:49:14Z")

</div>

> [@Bas](#):
>
> I would repport it to @ask so he can take action against that pool.  
> As typical company-pools have their own servers, at least I would expect them to have their own.

Anyone with a domain can put entries in it that point at anything else and there’;s absolutely nothing Ask can do about that outside of some obscure corners of trademark law.

OP is already doing as much as they can: report to Tesla, find others who are affected. I understood that to eb the purpose of this thread.

---

<div class="post-metadata">

**Author:** ![Bas](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/bas/32/465_2.png) [@Bas](https://community.ntppool.org/u/Bas)\
**Post date:** [September 10, 2026, 2:57pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/14 "2026-09-10T14:57:59Z")

</div>

> [@grifferz](#):
>
> Anyone with a domain can put entries in it that point at anything else and there’;s absolutely nothing Ask can do about that outside of some obscure corners of trademark law.

I know that. But Ask can remove the company-pool after giving a warning.  
Company-pools should not (ab)use ntp-servers without consent of the NTP-owner.

So yes, Ask can and should take action if they use servers that do not want to be in a company-pool.

In my opinion there should be an opt-in for servers to be used by a company.

---

<div class="post-metadata">

**Author:** ![robinpie](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/robinpie/32/2670_2.png) [@robinpie](https://community.ntppool.org/u/robinpie)\
**Post date:** [September 10, 2026, 3:26pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/15 "2026-09-10T15:26:29Z")

</div>

It’s a CNAME under [tesla.com](http://tesla.com). Ask cannot do that

---

<div class="post-metadata">

**Author:** ![michaelk](https://avatars.discourse-cdn.com/v4/letter/m/ccd318/32.png) [@michaelk](https://community.ntppool.org/u/michaelk)\
**Post date:** [September 10, 2026, 3:51pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/16 "2026-09-10T15:51:55Z")

</div>

Bas you really need to undersgand there is absolutely no obligation for you to participate in each and every thread in this forum. In particular the many many topics where you have no clue what you are talking about, you are more than welcome to stay out. On behalf of many of us - thank you!

---

<div class="post-metadata">

**Author:** ![Bas](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/bas/32/465_2.png) [@Bas](https://community.ntppool.org/u/Bas)\
**Post date:** [September 10, 2026, 4:07pm UTC](https://community.ntppool.org/t/my-server-is-being-included-in-what-seems-to-be-bungled-internal-tesla-vulnerability-scanning/4672/17 "2026-09-10T16:07:47Z")

</div>

> [@robinpie](#):
>
> It’s a CNAME under [tesla.com](http://tesla.com). Ask cannot do that

Just see it now, it’s a pool that is under [tesla.com](http://tesla.com), you are right, he can’t do that.  
My mistake.
