netsec-sig - Re: [Security-WG] I2 - Strange xntpd behavior
Subject: Internet2 Network Security SIG
List archive
- From: gcbrowni <>
- To:
- Subject: Re: [Security-WG] I2 - Strange xntpd behavior
- Date: Fri, 22 Sep 2017 11:50:01 -0400
- Ironport-phdr: 9a23:J3la4RTgG/yCV0jMQdADPHUJtNpsv+yvbD5Q0YIujvd0So/mwa69YxKN2/xhgRfzUJnB7Loc0qyN4vCmATRIyK3CmUhKSIZLWR4BhJdetC0bK+nBN3fGKuX3ZTcxBsVIWQwt1Xi6NU9IBJS2PAWK8TW94jEIBxrwKxd+KPjrFY7OlcS30P2594HObwlSijewZbB/IA+qoQnNq8IbnZZsJqEtxxXTv3BGYf5WxWRmJVKSmxbz+MK994N9/ipTpvws6ddOXb31cKokQ7NYCi8mM30u683wqRbDVwqP6WACXWgQjxFFHhLK7BD+Xpf2ryv6qu9w0zSUMMHqUbw5Xymp4qF2QxHqlSgHLSY0/mHLhcN/kaxVrhyhqQJ9zIDXe4yVO+ZyfqbHcN8GWWZMXMBcXDFBDIOmaIsPCvIMPelEoIbmvVsOqhW/BQ+tBOjyzTJIiWP50rYg0+QmHwDG2g0gEskBsHTQq9X6L70dUeSzzKnP0TrPdfJW2Srn5IfWbx8hvOiBULRtesTfzkkvEhnKjlSWqYH9PjOV0PgNvHaB7+pmS+2vl3ArpxtvrTey28chjJTCiIENyl3c6Cl0z4I4KcelREN6YdOoCoZcui+VOodsQM4vTGdlszsgxLIco560Zi0KxYwnxxHBb/yHdJCF4hf5W+aQJTd0nm5qeK6jiBqo/kig0Ov8Vs6o31pQrypFj8PAuW4Q2BzO8sSHS/198Vm92TuXygze5eVJLVopmafaK5Mt2KM8m5QcvEjZHCL7l136jKqMeUUl/uio5f7nYrLjppKEOI97lhrxMr4pms2xB+Q4MxMDX2ef+eS7z7Ls50n5QLNNjvIqiKXZsY3aKd4FqaGkHg9Zypwj5AqnDze6zNQYmmEKLElbdx2bkojpIVDOIOz4DPumjVWsnyxmx/THPr36HpXNNWbPnK3gfbZ7905T1hAzzdZB6JJIFL0NOuz8VVLstI+QMhhsKAG/3vzmFMQ4yYw2WGSTD7WfPb+I91KE+7EBOe6JMYAesiz6NP4kr6rhhnUjnkAbfIGm2ZwdYXS+Gf8gIljfbHbx1IRSWVwWtxYzGbS5wGaJViReMi6/
John: ntp.conf is as expected with just out NTP server in it, we don’t do outbound RE filters, and I don’t think A.B.C.D is an NTP server. I THINK this is somehow scanning related. I think. Andrew: Hard to address intervals. It’s not a pattern I can detect, although we do see it more often at certain time blocks. But it’s not a nice pretty pattern when time mapped. I doubt A.B.C.D is a legit attempt to request time. I THINK it’s either an attempt to amplify or a scan. I think. But that all assumes it’s a response to a packet coming in. I see this on multiple nodes and I see it from multiple source IP’s, although there are a few nodes and source IP’s that appear more often than others. I might get 5 in a 2-3 day period. Mirroring I thought about this. If syslog "port 123" doesn’t work then I’m suspicious that mirroring would turn anything up. It’s still an option, but it’s not high on the list because of the resources currently required.
|
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
- [Security-WG] I2 - Strange xntpd behavior, gcbrowni, 09/22/2017
- Re: [Security-WG] I2 - Strange xntpd behavior, Andrew Gallo, 09/22/2017
- Re: [Security-WG] I2 - Strange xntpd behavior, gcbrowni, 09/22/2017
- Message not available
- Re: [Security-WG] I2 - Strange xntpd behavior, John Kristoff, 09/22/2017
- Re: [Security-WG] I2 - Strange xntpd behavior, Richard Angeletti, 09/22/2017
- Re: [Security-WG] I2 - Strange xntpd behavior, gcbrowni, 09/25/2017
- Re: [Security-WG] I2 - Strange xntpd behavior, Andrew Gallo, 09/22/2017
- <Possible follow-up(s)>
- Re: [Security-WG] I2 - Strange xntpd behavior, John Kristoff, 09/22/2017
Archive powered by MHonArc 2.6.19.