On Nov 4, 2013, at 19:54, Justin <[email protected]> wrote:

> I have two machines that participate in the ntp pool project, and I received 
> an abuse email today. Basically, my server was DDOS someone else, ntp 
> reflection attack.

Hi Justin,

Can you show a tcpdump of this?

I got two other DDOS related reports in the last 24 hours (which is at least 2 
more than I recall getting in any given *month* or maybe even year in the last 
8!).

One was a straight up udp reflection attack (management packets, I think) - 
maybe similar to yours.

The other was udp packets, but not port 123 in either end. It looked like it 
was just a straight up "dump traffic that way" attack. That was multiple 
gigabits though.


Ask
_______________________________________________
pool mailing list
[email protected]
http://lists.ntp.org/listinfo/pool

Reply via email to