logoalt Hacker News

iancarrolltoday at 7:08 PM2 repliesview on HN

As a bug bounty researcher, my systems would do the same thing if they ended up georouted to this IP. *.tesla.com is marked as in scope on https://bugcrowd.com/engagements/tesla, and my agents will probe anything under there as it is presumed to have explicit authorization.

Not sure if there is a great solution, but I'm inclined to say that attack traffic like this is the new normal. In fact, the attack volume they got is quite small compared to the volume I have seen on other tech company subdomains - the new normal is probably much worse.


Replies

xmodemtoday at 7:38 PM

One solution is to not set up and run a computer program that relies on bad information to perform automated cyber-attacks on third parties.

show 1 reply