NTP server misuse and abuse
NTP vandalism is an expression that was first used by Poul-Henning Kamp in an open letter to the router manufacturer D-Link
The first known case of NTP vandalism was in may 2003, when netgear´s products flooded the University of Wisconsin’s NTP server with so many packets that it resulted in killing their server with a DDOS attack.
Latest known case is D-Links routers, that are contacting multiple Stratum 1 NTP servers, without respecting the restrictions of client types or geographical limitations. This resulting in a huge rise in traffic from thousands of private routers contacting the Stratum 1 servers, instead of D-Link’s own NTP servers.
Poul-Henning Kamp, who is the manager of the only Danish Stratum 1 server, made an investigation, to find out where the DDOS like amount of traffic came from.
He has been in contact with D-Link, but without being able to get any admittance, but has instead been accused of extortion, when presenting them for the bill for the extra traffic.
---
Links:
- http://www.cs.wisc.edu/~plonka/netgear-sntp/ - The Netgear incident
- http://people.freebsd.org/~phk/dlink/ - Poul-Henning Kamp’s open letter to D-Link
- http://people.freebsd.org/~phk/dlink/letter2.html - Poul-Henning Kamp’s open letter to the NTP community