Oh, and be sure to include "you're scanning a pool address so you're probably scanning a lot of other sites that don't belong to your customer". They should know it's potentially not one little web site.
I'm aware how much crap there is on the Internet, I just think the specific nature of this (legitimate commercial vuln scanner thinks I'm Tesla) is funny
It does bring attention to: how many other organizations are doing this?
Tesla is a large enterprise.
They almost certainly subscribe to some overpriced SaaS garbage which is manned by offshore drones who by definition do not care because they're not paid enough to care.
Unfortunately this isn't the 80s anymore where you can ring up a system administrator at a university and get a human on the other end.
I thought about trying this, but MPIC makes it very very very difficult (the round-robin has some geolocation magic baked in regarding what server it connects you to).
It's HTTP requests, not NTP requests, and the volume isn't the problem, it's that Assetnote is sending live exploit payloads /at all/ to a stranger on Tesla's behalf
Unlikely, but the lazy wonks could enable stratum 1 time services with the cars GPS/cellular receiver and RTC. Having done that for equipment in the past, we all know it is literary only $8.43/unit in parts. Also, setting ntp time as the tertiary fall back has been around for over a decade. =3
reply