Re: ntpd advisory not yet fixed?

Xin LI <[email protected]>
Newsgroups gmane.os.netbsd.devel.security
Message-ID <CAGMYy3uU+Fy8WGsjqf_4+GEc-RM+GY5WOnNONcUQgUdpg5FG3w@mail.gmail.com>
Well, I think it's always a good idea to have:

restrict default kod nomodify notrap nopeer noquery
restrict -6 default kod nomodify notrap nopeer noquery
restrict 127.0.0.1
restrict -6 ::1
restrict 127.127.1.0

in ntp.conf, if the server is intended to serve the public Internet.

The issue can not be easily fixed without losing functionality, by the
way.  We (FreeBSD) plans to issue an advisory that disables 'monitor'
feature by default on January 14.

On Fri, Jan 3, 2014 at 2:50 PM, John Klos <[email protected]> wrote:
> It looks like ntpd versions in netbsd-5 and netbsd-6 can be used for
> reflection attacks:
>
> http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-5211&cid=1
>
> Is anyone working on this?
>
> John



-- 
Xin LI <[email protected]> https://www.delphij.net/
FreeBSD - The Power to Serve! Live free or die
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.