If it were 8000 requests per second, this might be worthy of some investigation.
But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.
If it were 8000 requests per second, this might be worthy of some investigation.
But 8000 ntp requests alone consume far less than 1 us cent of compute + bandwidth. This isn't worth lifting a finger over.
"They tried all kinds of exploits against me: path traversal, webshell uploads, probing software internals, probing WordPress and other CMS management endpoints, SSRF, Log4Shell, and a lot more."
I don't go complaining on the internet about the absolute shitflood of compromised routers on broadband ISPs in Indonesia probing my stuff 24x7x365 because I know it would be futile. But if I found one specific american company that was repeatedly probing my stuff all the time? Maybe I'd escalate it.
But that obviously isn't what we're talking about here. We're talking about a massive multibillion dollar corporation breaking the rules of a community project they joined by committing a Jr Sysadmin grade fuck up and ghosting the people who's infrastructure they have now placed in the crosshairs of serious, enterprise grade automated vulnerability testing from a company who might now inadvertently be committing a felony.
That's a bit different than getting a few dozen lazy hits a day because some botnet got to your IP in the Shodan and saw the Plex port open.
The scanner is likely illegal.
The pointing is… so stupid nobody thought to make a law about it.