Over roughly the past two days, my HTTP server (that happens to be on the same IP as my NTP server) has received ~8,000 requests from 54.165.75.96 and 35.168.63.24, UA Assetnote/1.0.0 (ExposureScan), with many templated exploit payloads. Every payload used pool-ntp.tesla.com as the target hostname. I assume their asset inventory accidentally included that subdomain which does not actually point to Tesla assets.
I have emailed Tesla about this and am not concerned about it (I’m patched against everything they tried and I have no reason to believe this wasn’t an innocent accident). However I am curious if anyone else is seeing this, or if they resolved it to my IP once and kept hitting it.
If you’re talking about the pool-ntp tesla hostname, you understand that it’s a CNAME that points to the NTP pool, right? So if you visit it in a web browser you may see any web site that a random pool volunteer has running on their IP address.
If that’s not what you mean, can you elaborate? It’s very confusing to just keep thoring out these “it’s spam” “bullshit” responses.
Can you please explain what you are talking about? What web site that who gave?
$ host pool-ntp.tesla.com
pool-ntp.tesla.com is an alias for pool.ntp.org.
pool.ntp.org has address 212.71.233.40
pool.ntp.org has address 85.199.214.102
pool.ntp.org has address 94.15.142.187
pool.ntp.org has address 212.132.222.19
pool.ntp.org mail is handled by 0
This means the server Bas ran into is a legit NTP pool server that also happens to host a website. This is very common. https://www.ntppool.org/en/join.html says “… but sometimes people type pool.ntp.org and are then surprised to get a random web page” which is exactly what Bas is seeing here. In short, nothing to see here, move on. Next message in this topic better be about someone else seeing those scans in their logs, or something else that is relevant to the scanning. Let’s stop the spam thread here.
To restate more succintly: pool-ntp.tesla.com CNAMEs to pool.ntp.org. This is normal and fine. But it looks like that some Tesla automated scanner rolled my IP from it and is trying to exploit it. I can tell, because among their attacks, are attacks over HTTP, which include Host headers. Is anyone else seeing this?
I would repport it to @ask so he can take action against that pool.
As typical company-pools have their own servers, at least I would expect them to have their own.
Anyone with a domain can put entries in it that point at anything else and there’;s absolutely nothing Ask can do about that outside of some obscure corners of trademark law.
OP is already doing as much as they can: report to Tesla, find others who are affected. I understood that to eb the purpose of this thread.
I know that. But Ask can remove the company-pool after giving a warning.
Company-pools should not (ab)use ntp-servers without consent of the NTP-owner.
So yes, Ask can and should take action if they use servers that do not want to be in a company-pool.
In my opinion there should be an opt-in for servers to be used by a company.
Bas you really need to undersgand there is absolutely no obligation for you to participate in each and every thread in this forum. In particular the many many topics where you have no clue what you are talking about, you are more than welcome to stay out. On behalf of many of us - thank you!