‘Scraping’ our time servers
ID: 2c164850-87dd-54f9-9a49-1ae13b39e528
STIX ID: report--2c164850-87dd-54f9-9a49-1ae13b39e528
Feed Name: SensePost Blog
Threat Score
This blog post demonstrates that the NTP 'monlist' command can be queried to retrieve lists of recent client IPs (up to ~600), enabling footprinting and exposing internal/private addresses; it also explains how spoofed monlist queries can be leveraged for large DDoS amplification (authors cite a possible ~30 Gbps attack), and includes a Python tool and Maltego transforms used to enumerate South African NTP servers and their clients.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
