当前位置:网站首页>Patch NTP server at the beginning of DDoS counterattack
Patch NTP server at the beginning of DDoS counterattack
2022-07-06 02:31:00 【zy18165754120】
According to the DDoS Defense company NSFOCUS call ,IT The industry seems to be right 2014 Relevant at the beginning of the year DDoS The warning of amplifying the increasing risk of attack has responded well , Patched a large number of vulnerable servers .
The US provider announced on Tuesday New statistics , call 3 Global vulnerability in January NTP The number of servers is about 21,000 platform ,5 The month fell again to 17,600 platform . This is lower than 2013 year 12 Of the month 432,120 people .
however , The system administrator still needs to finish the work . The report also claims that , It can enlarge the flow 700 Times more NTP The number of amplifiers has increased from 12 Of the month 1,224 One added to today's 2,100 individual .
“US-CERT And network time protocol strongly recommend that system administrators ntpd Upgrade to 4.2.7p26 Or later ,”NSFOCUS say .
“4.2.7p26 Users of earlier versions should use noquery To block all status queries , Or use disable monitor To disable ntpdc –c monlist command , At the same time, other status queries are still allowed .”
As early as 1 month , The United States CERT Just warn , Using public server NTP Zoom in DDoS The threat of attack is growing .
If it's not properly protected , The global NTP The ubiquity of servers makes them potentially dangerous agents for such attacks . A series of connected devices are used NTP To synchronize their clocks .
Attackers can get through “monlist” Query the last of the requests to connect to the server 600 individual IP List of addresses , Thus, it is quite easy to take advantage of open NTP The server .
Then what they need to do is disguise the source address as the victim's source address , Overwhelm them by sending a large number of results IT System .
Suggest upgrading to a new one NTP Version will be automatically disabled monlist function .
Network security company Incapsula stay 3 A project released in September DDoS Threat situation Research Show , since 1 Since the month ,NTP Amplification attacks have undergone a major shift , Maximum attack reached 180Gbps.
边栏推荐
- [coppeliasim] 6-DOF path planning
- 【机器人库】 awesome-robotics-libraries
- Global and Chinese markets of general purpose centrifuges 2022-2028: Research Report on technology, participants, trends, market size and share
- VIM usage guide
- 2022年版图解网络PDF
- Bigder:34/100 面试感觉挺好的,没有收到录取
- 【MySQL 15】Could not increase number of max_ open_ files to more than 10000 (request: 65535)
- Global and Chinese markets of screw rotor pumps 2022-2028: Research Report on technology, participants, trends, market size and share
- 怎么检查GBase 8c数据库中的锁信息?
- Pat grade a 1033 to fill or not to fill
猜你喜欢
2022年版图解网络PDF
[Yunju entrepreneurial foundation notes] Chapter II entrepreneur test 8
Adapter-a technology of adaptive pre training continuous learning
Pat grade a 1033 to fill or not to fill
Audio and video engineer YUV and RGB detailed explanation
A doctor's 22 years in Huawei
力扣今日题-729. 我的日程安排表 I
The ECU of 21 Audi q5l 45tfsi brushes is upgraded to master special adjustment, and the horsepower is safely and stably increased to 305 horsepower
技术管理进阶——什么是管理者之体力、脑力、心力
[community personas] exclusive interview with Ma Longwei: the wheel is not easy to use, so make it yourself!
随机推荐
Multi function event recorder of the 5th National Games of the Blue Bridge Cup
2020.02.11
Paper notes: graph neural network gat
[Yunju entrepreneurial foundation notes] Chapter II entrepreneur test 8
[Yunju entrepreneurial foundation notes] Chapter II entrepreneur test 11
力扣今日題-729. 我的日程安排錶 I
【机器人手眼标定】eye in hand
Shell脚本更新存储过程到数据库
Ue4- how to make a simple TPS role (II) - realize the basic movement of the role
有沒有sqlcdc監控多張錶 再關聯後 sink到另外一張錶的案例啊?全部在 mysql中操作
Formatting occurs twice when vs code is saved
Black high-end responsive website dream weaving template (adaptive mobile terminal)
剑指 Offer 30. 包含min函数的栈
零基础自学STM32-野火——GPIO复习篇——使用绝对地址操作GPIO
Adapter-a technology of adaptive pre training continuous learning
Déduisez la question d'aujourd'hui - 729. Mon emploi du temps I
【MySQL 15】Could not increase number of max_ open_ files to more than 10000 (request: 65535)
【社区人物志】专访马龙伟:轮子不好用,那就自己造!
MySQL winter vacation self-study 2022 11 (5)
[Yunju entrepreneurial foundation notes] Chapter II entrepreneur test 15