What is all this ntp traffic at startup? (Solved)

For discussions about security.
Post Reply
Message
Author
ccaaee
Posts: 48
Joined: Sat 27 Feb 2010, 17:10

What is all this ntp traffic at startup? (Solved)

#1 Post by ccaaee »

Hello

I'm running tcpdump on a separate server watching traffic on an installed-to-hd puppy (Precise Puppy version 5.6).
When this puppy starts up there is a flood of ntp requests to strange and dubious sounding sites.

Does anyone have any what is going on?

thanks
Last edited by ccaaee on Wed 02 Sep 2015, 17:26, edited 1 time in total.

User avatar
Moose On The Loose
Posts: 965
Joined: Thu 24 Feb 2011, 14:54

Re: ntp at startup

#2 Post by Moose On The Loose »

ccaaee wrote:Hello

I'm running tcpdump on a separate server watching traffic on an installed-to-hd puppy (Precise Puppy version 5.6).
When this puppy starts up there is a flood of ntp requests to strange and dubious sounding sites.

Does anyone have any what is going on?

thanks
Perhaps psync is messed up.
The version that came with 528 could be messed up by one of its configuration files being wrong. Try setting up psync again and see if it stops happening

ccaaee
Posts: 48
Joined: Sat 27 Feb 2010, 17:10

#3 Post by ccaaee »

To make a long story short psync ends up by calling :
ntpdate europe.pool.ntp.org

Now, I don't know how europe.pool.ntp.org is controlled but by running ntpdate europe.pool.ntp.org I see some of the funniest names (eg. mafia.org). Is anyone aware of security risks associated with ntp?

User avatar
Moose On The Loose
Posts: 965
Joined: Thu 24 Feb 2011, 14:54

#4 Post by Moose On The Loose »

ccaaee wrote:To make a long story short psync ends up by calling :
ntpdate europe.pool.ntp.org

Now, I don't know how europe.pool.ntp.org is controlled but by running ntpdate europe.pool.ntp.org I see some of the funniest names (eg. mafia.org). Is anyone aware of security risks associated with ntp?
I have a vague memory of something in the past. It was more a matter of a denial of service attack than anything. There was a way to get NTP servers to send huge amounts of data to a victim.

ccaaee
Posts: 48
Joined: Sat 27 Feb 2010, 17:10

#5 Post by ccaaee »

thanks for this

I just replaced psync with a script running ntpdate to another ntp server here in europe

C

Post Reply