5 ms·
firmware sends six DNS requests and one NTP query every 5 seconds (...snip...) TP-Link has hardcoded the following non-configurable NTP servers and serv
by kees99 9y ago
firmware sends six DNS requests and
one NTP query every 5 seconds
(...snip...)
TP-Link has hardcoded the following non-configurable
NTP servers and server pools in their firmware:
(...snip...)
au.pool.ntp.org, nz.pool.ntp.org
Wait... so TP-Link is effectively DDoSing NTP pool?
Also, as pointed out in another thread here, vendor using country prefix instead of applying for their own prefix is a violation of:
http://www.pool.ntp.org/en/vendors.html http://www.pool.ntp.org/en/vendors.html
..which was put in place as a reaction to incidents just like this one:
https://en.wikipedia.org/wiki/NTP_server_misuse_and_abuse#Notable_cases https://en.wikipedia.org/wiki/NTP_server_misuse_and_abuse#No...
- zaarn 9y agoA NTP request every couple seconds is similarly in violation of the vendor guidelines, once every 10 minutes or less often is stated.
- nacs 9y agoWould it be possible for the NTP server to detect what type of device/OS is sending the request and block it (ie: could au/nz.pool.ntp.org servers block all TP-Link requests to teach them a lesson)? If they can't do that maybe they can just detect IPs that are making requests every 5 seconds as the TP-Link products are doing and block those since they're in violation of the once-every-10-minutes-maximum rule for the NTP servers)?
- samstave 9y agoOut-of-the-loop: what products are using TP-Link? Aside: maybe there should be a governing body for comm protocol behavior? (Semi sarcastic)
- ganoushoreilly 9y agoTP-link is a manufacturer of multiple devices and an OEM for others. I would imagine, if consistent across firmwares, there are a lot of requests being made. https://en.wikipedia.org/wiki/TP-Link https://en.wikipedia.org/wiki/TP-Link
- mattstreet 9y agoI'm a bit rusty, but I believe the way NTP works (at least the reference version which is commonly used) is that if a client sends too many requests in a short time, they are ignored except to reply with a "back off packet" which is called the KoD (Kiss of death) in NTP terms. Security audits have found some issues with abusing the KoD so I'm not sure if it still works like that or if it tends to be disabled. (I was on one of the teams doing the audit, I found the "Skeleton Key" defect) https://www.eecis.udel.edu/~mills/ntp/html/rate.html#kiss https://www.eecis.udel.edu/~mills/ntp/html/rate.html#kiss If you wanted to help the server deal with DoS even better, I would guess the best solution is to put a rate limiting firewall in front of it.