Re: ntpd advisory not yet fixed?
Xin LI <[email protected]>
| Newsgroups | gmane.os.netbsd.devel.security |
|---|---|
| Message-ID | <CAGMYy3uU+Fy8WGsjqf_4+GEc-RM+GY5WOnNONcUQgUdpg5FG3w@mail.gmail.com> |
Well, I think it's always a good idea to have: restrict default kod nomodify notrap nopeer noquery restrict -6 default kod nomodify notrap nopeer noquery restrict 127.0.0.1 restrict -6 ::1 restrict 127.127.1.0 in ntp.conf, if the server is intended to serve the public Internet. The issue can not be easily fixed without losing functionality, by the way. We (FreeBSD) plans to issue an advisory that disables 'monitor' feature by default on January 14. On Fri, Jan 3, 2014 at 2:50 PM, John Klos <[email protected]> wrote: > It looks like ntpd versions in netbsd-5 and netbsd-6 can be used for > reflection attacks: > > http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-5211&cid=1 > > Is anyone working on this? > > John -- Xin LI <[email protected]> https://www.delphij.net/ FreeBSD - The Power to Serve! Live free or die