Showing posts with label NTP. Show all posts
Showing posts with label NTP. Show all posts

Friday, 23 October 2015

Vulnerabilities In Network Time Protocol (NTP) DoS Permit



In the Network Time Protocol (NTP) Multiple vulnerabilities have been identified that could allow attackers to systems that make use of NTP can cause a Denial of Service (DoS). NTP is a protocol that allows systems to synchronize the time for different services and applications.

It is present in network devices and embedded devices', as well as desktop and server operating systems, including Mac OS X, various Linux distributions and BSD-based systems. Decided last year to start the Linux Foundation on the occasion of the Heart Bleed vulnerability Core Infrastructure Initiative (CII) with the aim of securing popular open source projects on the Internet. Cisco is part of the CII and focuses on researching NTP.

Researchers at Cisco have a total of eight vulnerabilities discovered in NTP, which in ntp-4.2.8p4 been resolved. Also five other leaks are history. In addition to a Denial of Service are also bug fixes are causing memory corruption or path traversal were possible. The only vulnerability that is too general, according to the developers of NTP abuse is concerned a bug allowing attackers with NTP servers for DDoS attacks can deploy. In August, warned the FBI for DDoS attacks that uses the Network Time Protocol.

Sunday, 21 December 2014

Critical vulnerabilities Found in Network Time Protocol (NTP)



Researchers at Google have critical vulnerabilities in the Network Time Protocol (NTP) allowing attackers discovered on systems that use NTP can execute code. NTP is a protocol that allows systems to synchronize the time for different services and applications.

It is used among other things on a large scale industrial systems. Neel Mehta and Stephen Roettger of the Google Security Team discovered several vulnerabilities in the protocol. In the worst case, an attacker by sending a single packet to cause a buffer overflow, and it is now possible to carry out on the attacked system code with the rights of the NAP-process. This vulnerability is present in all versions of NTP NTP-4.2.8.

Before warn the the Industrial Control Systems Cyber ​​Emergency Response Team (ICS-CERT) of the US Government, the US Computer Emergency Readiness Team ( US-CERT ) and the CERT Coordination Center ( CERT-CC ) at Carnegie Mellon University. Administrators also are advised to upgrade to NTP 4.2.8. Furthermore, this version fixes vulnerabilities in the random number generator allow an attacker to retrieve certain information. Exploits that make the leak abuse have been found on the Internet, according to the ICS-CERT