[Discuss] NTP Gone Crazy?

David N. Blank-Edelman dnb at ccs.neu.edu
Sun Jan 12 15:54:34 EST 2014


On 12 Jan 2014, at 15:45, Kent Borg wrote:

> but I am thinking running such obsolete code when this is a hot target 
> is also a bad idea.

Understood. I just ran the following and found some more potential 
reflectors on my net, recommend others do the same:

$ sudo nmap -sU -pU:123 -Pn -n --script=ntp-monlist {target 
host/network}

The hosts that give back real ntp peer information (vs. just showing as 
having NTP in use) are those that need to be clamped down pronto.

         -- dNb



More information about the Discuss mailing list