oss-sec mailing list archives
Re: shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes
From: Richard Johnson <rdump () river com>
Date: Wed, 27 Jan 2016 11:07:17 -0700
On 2016-01-27 06:05, Loganaden Velvindron wrote:
Shouldn't we have some kind of policy for operators participating in pool.ntp.org to prevent such issues ?
If the issue is 'port scanning by the IPv6 NTP pool participant', why bother? Any IPv6 NTP pool provider will naturally have peer IPv6 addresses to use and record. It's one way that researchers at measurement organizations already track IPv6 use and growth. Others can, do, and will use popular public services like NTP to enumerate and record active peer addresses as well. And some of those others will do things with that data. A policy that says "do not log peer addresses" would be nice for privacy reasons, and bad for maintenance reasons. Practically speaking, violations will be undetectable, and it'll be unenforceable. Maybe a policy that says 'do not engage in DoS' instead? Either way, when we don't want to be scanned, regardless of how the scanner gets their target addresses, we tend to use perimeter firewalls. Richard
Current thread:
- shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes Luca BRUNO (Jan 27)
- Re: shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes Loganaden Velvindron (Jan 27)
- Re: shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes Richard Johnson (Jan 27)
- Re: shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes Thomas B . Rücker (Jan 27)
- Re: shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes Kurt Seifried (Jan 27)
- Re: shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes Zach W. (Jan 27)
- Re: shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes Hazel (Jan 29)
- Re: shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes enki (Jan 29)
- Re: shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes Scott Herbert (Jan 29)
- Re: shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes Daniel Micay (Jan 29)
- Re: shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes Daniel Micay (Jan 29)
- Re: shodan.io actively infiltrating ntp.org IPv6 pools for scanning purposes Loganaden Velvindron (Jan 27)