5 ms·
How do you test a server for this attack? I want to make sure my servers don't participate.
by poobrains 13y ago
How do you test a server for this attack? I want to make sure my servers don't participate.
- jadc 13y agohttp://openntpproject.org/ http://openntpproject.org/
- m-arnold 13y agoYou can use ntp client: ntpdc -c monlist 1.2.3.4 For more info see my blog post (it is related to VMware ESXi but instructions are useful for any ntpd): http://ar0.me/blog/en/posts/2014/01/howto-prevent-malicious-usage-of-vmware-esxi-in-ntp-reflection-attacks.html http://ar0.me/blog/en/posts/2014/01/howto-prevent-malicious-...
- biot 13y agoThe fine article states: You can check whether there are open NTP servers that support the MONLIST command running on your network by visiting the Open NTP Project[0]. Even if you don't think you're running an NTP server, you should check your network because you may be running one inadvertently. [0] links to http://openntpproject.org/ http://openntpproject.org/
- e12e 13y agoAs I happen to have openntpd installed on a box I attempted to test this from (in Debian that package conflicts with ntp -- which includes the ntpdc client) -- I also found this: https://github.com/sensepost/ntp_monlist https://github.com/sensepost/ntp_monlist It at least correctly identifies ntp0.ovh.net as responding -- and seems to match up with what openntpproject.org thinks... [edit: apparently this (partly) also illustrates why more people should heed the advice to "run only what you need, listen only where you must" -- or in other words, make sure that: netstat -lnutp # listening, numerical, udp, tcp, program gives essentially no output, at the very least not a lot of 0.0.0.0:x (listening on all interfaces). I'm always a little sad when people don't check that, and just throw up some complicated iptables-rules -- before checking if they're actually running some daemons that should be removed, or pointed at less public interfaces.]
- devicenull 13y agoDon't forget to test your IPMI controller as well, if you have that exposed to the internet!
- duskwuff 13y agoThose really shouldn't be exposed to the Internet, full stop.
- jlgaddis 13y ago$ nmap -sU -pU:123 -Pn -n --script=ntp-monlist <target> Note that that only checks if the target responds to the monlist command.