What are the NTP 3 vulnerabilities?


 
Thread Tools Search this Thread
Operating Systems Solaris What are the NTP 3 vulnerabilities?
# 1  
Old 01-07-2010
What are the NTP 3 vulnerabilities?

Hi Guru

I need to know which version of NTP is install in Solaris 10 box. How can I check it.

IF NTP 3 in implemented then somebody told me implement NTP 4 due to security reasons, for that I have to tell what are the vulnerabilities present in NTP 3 to higher authorities. I could not able to get vulnerabilities present in NTP 3 through google. Kindly help me in this regard

Regards
# 2  
Old 01-07-2010
The time on your systems could be subverted a causing denial attack.
Whch ever version of NTP you are using if you are in control of your NTP server you can make your NTP system use an encryption key, according to this page:
http://www.eecis.udel.edu/~mills/ntp/html/keygen.html
what they are proposing requires NTPv4 to be used.

This:
ConfiguringAutokey < Support < NTP
may help in setting this up.

and this page:
http://support.ntp.org/bin/view/Main/SecurityNotice
carries security notices relating to NTP.

Last edited by TonyFullerMalv; 01-07-2010 at 05:39 PM..
# 3  
Old 01-07-2010
Solaris Version 9 (SunOS 5.9) and earlier have the xntpd version 3 protocol see RFC 1305.., The most current protocol is version 4 - only RFC 2030 exists now for it. This is not complete.

Read your man page - it tells you the default protocol for xntpd (NTP)

I am not aware of specific problems. Go to the ntp website and search in reports there.
ntp.org: Home of the Network Time Protocol

---------- Post updated at 14:36 ---------- Previous update was at 14:35 ----------

Tony -
do you have a link for the denial of service attack warning?
# 4  
Old 01-07-2010
No, it is something I was aware of at the back of my mind, could well only apply to earlier NTP protocols, I did a lot of work with NTP and a time receiver back in 1999...
# 5  
Old 01-08-2010
thanks for your inputs Guys, its a great knowledge sharing on NTP

Keep it up

Last edited by girish.batra; 01-08-2010 at 10:12 AM..
# 6  
Old 01-08-2010
Thanks for the kind Inputs....gurus. Its helped me a lots
Login or Register to Ask a Question

Previous Thread | Next Thread

8 More Discussions You Might Find Interesting

1. Red Hat

Ntp client sync with local over ntp server

Hi, I have two ntp servers in my cluster and I want all the nodes in my cluster to sync with either of the ntp servers or just one. Unfortunately it keep rotating the sync, between my ntp server 1, ntp server 2 and local. Is there anyway I can change the sync to avoid local? # ntpq -p ... (3 Replies)
Discussion started by: pjeedu2247
3 Replies

2. HP-UX

Setting up NTP HP-UX clients from solaris NTP server

Hi I wonder if its possible to setup NTP clients running HP-UX o.s. from a solaris 10 NTP server? FR (3 Replies)
Discussion started by: fretagi
3 Replies

3. Linux

How often does Linux NTP server update its time with the external NTP server?

All here, thank you for listening. Now I've set up a Linux NTP server by adding a external windows NTP server in /etc/ntp.conf. Then I start the ntpd daemon. But how often does the Linux NTP server update its time with the external NTP server? I've looked up everywhere but found no information... (1 Reply)
Discussion started by: MichaelLi
1 Replies

4. Solaris

Ntp

Hello I use Solaris 10 and I have NTP packages arlrady installed pkginfo | grep -i ntp system SUNWntpr NTP, (Root) system SUNWntpu NTP, (Usr) How to configure NTP? thanks (2 Replies)
Discussion started by: melanie_pfefer
2 Replies

5. Solaris

Question about NTP

Hi i have question about NTP Client OS: Solaris 10 (11/06) I'm create /etc/inet/ntp.conf and remove /etc/inet/ntp.client In ntp.conf : server 10.0.0.1 server 10.0.0.2 # svcadm enable ntp # svcs -a | grep ntp online 12:48:16 svc:/network/ntp:default # ntpq ntpq>... (1 Reply)
Discussion started by: jess_t03
1 Replies

6. Solaris

ntp server and ntp client

All, How do you set a Solaris 9 server which received ntp updates from a ntp server to broadcast them on a local subnet. I have created a /etc/inet/ntp.conf file to receive the updates from a server on network and need to make this server become like a ntp relay from the main server. Any... (1 Reply)
Discussion started by: bubba112557
1 Replies

7. IP Networking

Ntp

How can I install ntp on AIX (4.3-5.1) ? thnx (1 Reply)
Discussion started by: Gismo
1 Replies

8. UNIX for Advanced & Expert Users

NTP and 11.i .....

Hi there! Does anybody know if HP-UX 11.i supports NTP? If yes, what version on NTP should be used? Thanx (1 Reply)
Discussion started by: penguin-friend
1 Replies
Login or Register to Ask a Question