Operator Says Tesla-Linked Scanners Are Hitting His NTP Server
A volunteer NTP server operator says AWS-hosted scanners carrying Tesla's pool-ntp hostname have thrown more than 50,000 exploit attempts at his hobbyist machine since August 21.
Robin, the operator of the dreamstation.systems hobbyist server, noticed something odd in his nginx logs in late August: persistent attack traffic from three IP addresses that arrived with Host or Referer headers naming pool-ntp.tesla.com, carried Assetnote user agents, and tried to make his server call back to Assetnote SSRF endpoints. The three scanners were 54.165.75.96, 35.168.63.24 and 52.44.200.251, all in Amazon's AWS address space.
A CNAME that points at volunteers
Assetnote is a legitimate attack surface management tool, now marketed as Searchlight Cyber, that runs continuous exposure scans against customer assets. Robin's theory is that the scanner is not targeting him on purpose. Tesla publishes pool-ntp.tesla.com as a CNAME to pool.ntp.org, the volunteer NTP Pool that round-robins requests across thousands of servers, and his machine is one of those volunteers.
If asset discovery pulled in everything it could find under tesla.com, including pool-ntp.tesla.com, and then resolved it, any IP that hostname answers with — including his own 67.215.249.229 — can be filed as a Tesla asset and become in scope for active scanning. He emailed Tesla's vulnerability reporting address, with no reply yet, to warn that the company may be “throwing exploits at strangers' IPs”.
What the scanner tried
The payloads covered path traversal, webshell uploads, probes of software internals, WordPress and other CMS management endpoints, SSRF and Log4Shell. In total 989 requests embedded assetnote-callback.com hostnames for Log4Shell and Text4Shell detection, and 114 named canary.assetnotessrf.com for SSRF.
One puzzle: fifteen requests carried a Host header of login.solarcity.com and asked for GET /(S(x))/b/(S(x))in/System.Web.Mvc.dll, an ASP.NET trick that tries to resolve /b/(S(x))in/ to /bin/. Sweeping the headers and query strings also turns up hostnames baked into the scanner's templates, among them servicemcdonalds.com, saferas.com and disneyfineart.com, plus one RFC 1918 address, 192.168.178.222. The scanner also speaks HTTP on every port it finds, so the author's SSH, Postfix and Dovecot services get junk HTTP traffic.
Still running
On 8 September Robin began answering requests for the pool-ntp.tesla.com hostname with non-standard status code 299 and a short notice on every path explaining that the machine is not Tesla infrastructure. The behaviour has not changed. None of the attacks have succeeded, and since 21 August he has logged more than 50,000 requests from Assetnote hosts.
Asked on the NTP Pool operators' board whether others running a web server on the same IP as their NTP server were seeing the same thing, one operator, Matt Nordhoff, said he had been seeing it since 15 August, with 9,126 requests from 54.165.75.96, 7,461 from 35.168.63.24 and 6,123 from 52.44.200.251. Nobody else has reported it. Robin wonders whether the scanner re-resolves the hostname every time, or simply collected a few pool addresses and keeps hammering those. He says he could firewall the addresses, but prefers to watch the traffic and make someone at Tesla aware of it.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.