Re: [chrony-users] prevent amplification attack |
[ Thread Index |
Date Index
| More chrony.tuxfamily.org/chrony-users Archives
]
- To: chrony-users@xxxxxxxxxxxxxxxxxxxx
- Subject: Re: [chrony-users] prevent amplification attack
- From: Miroslav Lichvar <mlichvar@xxxxxxxxxx>
- Date: Mon, 13 Dec 2021 09:52:51 +0100
- Authentication-results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=mlichvar@xxxxxxxxxx
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1639385578; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=5gpXG/p391bG+C54BOJd8Xcv1ZHLYglzWdADZPQTvk8=; b=Zv/G6vBQT7ELFGPmG93rNGXBijNdnCBaFRPqo4ap0k4Uk4rSkirhMfAqqRRhYxzeLSPFdN 1Xu6ZxZtJQX2fkbnQFYzWPlZ+oRAcH88UKWkzgJqucDXtIZFl/3Ts0yxFKD2D84wDLKoRZ shUQRDyZT97qge4P1Eg9LDmUxJ3ZArg=
On Thu, Dec 09, 2021 at 07:14:57PM +0100, Adrian Zaugg wrote:
> Hi there
>
> My network is monitored by shadowserver.org and it reports for my chrony
> instance, that it may be used in amplification attacks because it responded to
> "ntp mode 6 query READVAR". [1]
>
> They suggest to test with
> ntpq -c rv <my ntp server's ip>
> How can I properly test whether it is true what shadowserver.org claims and
That command is ok. I'd suspect a bug in their monitoring tools.
I had a similar case, when OVH was claiming a public server was
involved in NTP amplification attack and their packet capture showed
just normal client/mode NTP traffic.
> how can I prevent chronyd to not answering such queries, if it did?
chronyd doesn't support the NTP mode 6 or 7. It never did. There is no
unsecure configuration wrt amplification. It also has an extra check
to make sure it doesn't send a response larger than the request in
case there was a bug adding an unexpected extension field, etc.
--
Miroslav Lichvar
--
To unsubscribe email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "unsubscribe" in the subject.
For help email chrony-users-request@xxxxxxxxxxxxxxxxxxxx
with "help" in the subject.
Trouble? Email listmaster@xxxxxxxxxxxxxxxxxxxx.