NTP amplification attacks

A 5 star hangout for overworked and underpaid system admins.
Post Reply
User avatar
avij
Retired Moderator
Posts: 3046
Joined: 2010/12/01 19:25:52
Location: Helsinki, Finland
Contact:

NTP amplification attacks

Post by avij » 2014/01/15 20:59:01

For those running ntpd, please make sure your server is not being used for amplification attacks. I chose to add "noquery" to my "restrict default" line in ntp.conf for the time being, although doing that will block other less harmful query types as well. This configuration change does not affect regular time queries from your clients. Read the referenced links for more information.

The default configuration in ntp.conf as provided by CentOS does have the "noquery" already set. If you have tinkered with your ntp config, please make sure the configuration is still safe.

Post Reply