Jump to content

NTP server misuse and abuse

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by Yehaah~enwiki (talk | contribs) at 12:59, 9 April 2006 (NTP Vandalism started). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.
(diff) ← Previous revision | Latest revision (diff) | Newer revision → (diff)

NTP vandalism is an expression that was first used by Poul-Henning Kamp in an open letter to the router manufacturer D-Link

The first known case of NTP vandalism was in may 2003, when netgear´s products flooded the University of Wisconsin’s NTP server with so many packets that it resulted in killing their server with a DDOS attack.

Latest known case is D-Links routers, that are contacting multiple Stratum 1 NTP servers, without respecting the restrictions of client types or geographical limitations. This resulting in a huge rise in traffic from thousands of private routers contacting the Stratum 1 servers, instead of D-Link’s own NTP servers.

Poul-Henning Kamp, who is the manager of the only Danish Stratum 1 server, made an investigation, to find out where the DDOS like amount of traffic came from.

He has been in contact with D-Link, but without being able to get any admittance, but has instead been accused of extortion, when presenting them for the bill for the extra traffic.

---

Links: