IPv6 SpecialTests

From timswiki
Revision as of 23:14, 15 February 2014 by Wikiadmin (talk | contribs)
Jump to navigation Jump to search

IPv6 Special Tests

IPscan includes the following tests to exercise known weak protocols, or protocols which when poorly configured, can be exploited.


It is important to note that the same exploits may well apply to IPv4 hosts running the same protocols.


NTP Monitor List Query (UDP/161[1])

The NTP protocol, in earlier versions, supported a feature which reported a list of up to 600 clients which had used the queried NTP server as their time reference.

If an attacker uses a spoofed source address then a victim can be flooded with considerable NTP traffic. The size of the response is typically considerably larger than the request and consequently the attacker is able to amplify the volume of traffic directed at the victim. Additionally, because the responses are legitimate data coming from valid servers, it is especially difficult to block these types of attacks. The solution is to disable “monlist” within the NTP server or to upgrade to the latest version of NTP (4.2.7) which disables the “monlist” functionality.

As all versions of ntpd prior to 4.2.7 are vulnerable by default, the simplest recommended course of action is to upgrade all versions of ntpd that are publically accessible to at least 4.2.7. However, in cases where it is not possible to upgrade the version of the service, it is possible to disable the monitor functionality in earlier versions of the software.

To disable “monlist” functionality on a public-facing NTP server that cannot be updated to version 4.2.7, add the “noquery” directive to the “restrict default” line in the system’s ntpd.conf, as shown below:

restrict default kod nomodify notrap nopeer noquery
restrict -6 default kod nomodify notrap nopeer noquery

See CVE-2013-5211 for further details.





<adsense>1</adsense>