Network Time Protocol (NTP) Mode 6 Scanner

medium Nessus Plugin ID 97861

Synopsis

The remote NTP server responds to mode 6 queries.

Description

The remote NTP server responds to mode 6 queries. Devices that respond to these queries have the potential to be used in NTP amplification attacks. An unauthenticated, remote attacker could potentially exploit this, via a specially crafted mode 6 query, to cause a reflected denial of service condition.

Solution

Restrict NTP mode 6 queries.

See Also

https://ntpscan.shadowserver.org

Plugin Details

Severity: Medium

ID: 97861

File Name: ntp_mode6_query.nasl

Version: 1.2

Type: remote

Family: Misc.

Published: 3/21/2017

Updated: 5/7/2018

Supported Sensors: Nessus

Vulnerability Information

Required KB Items: Services/udp/ntp