Full Skyway Support Library

What are NTP Service Mode 6 Queries, what is the risk and how can you mitigate that risk?

The remote NTP server responds to mode 6 queries (Mode 6 is the recommended protocol used to get status information from a running ntpd to configure some of its behaviors on the fly). Devices that respond to these queries have the potential to be used in NTP amplification attacks. An attacker sends a massive amount of mode 6 messages to a huge number of recipient servers or clients in your organization. A remote attacker could potentially exploit this, via a specially crafted mode 6 query, to cause a reflected denial of service condition. Reflection Denial of Service attacks makes use of a third party component to send the attack traffic to a victim, ultimately hiding the attackers’ own identity. The attackers send packets to the reflector servers with a source IP address set to their victim’s IP, indirectly overwhelming the victim with the response packets.

Sources: www.netsecaddict.com; www.security.radware.com