Original release date: January 10, 2014
via US-CERT: The United States Computer Emergency Readiness Team http://www.us-cert.gov/ncas/current-activity/2014/01/10/Network-Time-Protocol-NTP-Amplification-Attacks
A vulnerability in the "monlist" feature of NTP can allow remote attackers to cause distributed denial of service attack (DDoS) via forged requests. US-CERT and the Canadian Cyber Incident Response Center (CCIRC) have both observed active use of this attack vector in recent DDoS attacks.
US-CERT encourages users and administrators to review the CCIRC document as well as US-CERT Vulnerability Note VU#348126 for more information.
This product is provided subject to this Notification and this Privacy & Use policy.
via US-CERT: The United States Computer Emergency Readiness Team http://www.us-cert.gov/ncas/current-activity/2014/01/10/Network-Time-Protocol-NTP-Amplification-Attacks
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.