Beste,
Als bijdrage aan het NTP project host ik een NTP server op al mijn servers. Nu kreeg ik daar vorige week een abusemelding in verband met mijn NOC vps:
Dear Abuse Department,
You received this email because your email is listed on the whois contact information of this IP.
Please be advised, our firewall detected a large DDOS flood, some traffic in this attack were originated from your network.
The IP in your network participated in this attack was 46.28.43.66. The device sending this traffic might be compromised or misused.
Please investigate into this issue and suspend any offensive devices ASAP.
Below are flow samples taken by our routers during a period of the attack, which including timestamp, duration of this sample, protocol, source IP and source port, destination IP and port, number of packets received, number of bytes received and
number of the flows received of this sample.
If you have any feedback or question, please feel free to reply
this email. We appreciate your effort on this matter.
NTP server owners: Please set rate limit, a lot of ddos attacks are now using NTP servers to reflect.
Time Zone is PST (GMT-8:00)
Date_flow_start Duration Proto
Src_IP_Addr:Port Dst_IP_Addr:Port Packet Bytes Flows
2013-11-03 22:38:23.436 65.400 17 46.28.43.66:123 - 162.218.48.78:80 292480 136880640 3
Network Operating Center
CNSERVERS LLC
+1.9713276731
Nu heb is deze VPS per direct uitgezet, en re-installed zonder NTP (voor alle zekerheid).
Echter... Nu blijk ik thuis (waar de eigenlijke servers staan) dezelfde problemen te hebben!
Zie bvb http://www.dcmerelbeke.be/feiten.html voor de statistiekjes. En dan moet ik nog vermelden dat dit een lijntje is met 25mbit down en 10mbit up. Hier staan momenteel een 5-tal servers te draaien op dat lijntje die allen NTP draaien. De servers op zich draaien nog wat vps'jes maar deze ip's zijn niet gekend als publieke NTP servers.
Iemand een idee hoe dit kan tegen gegaan worden? Behalve gewoon NTP uit zetten![]()

Likes:


Quote