Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: need suggestion xntpd a security hole ???
From: Claudio Telmon <claudio @ DI . Unipi . IT>
Organization: Dipartimento di Informatica, Universita' di Pisa, Italy
Date: Fri, 04 Jul 1997 15:41:56 +0200
To: Bret Watson <Bret . Watson @ bwa . net>
Cc: Dirk Nerling <Dirk . Nerling @ pdv . de>, firewalls @ GreatCircle . COM
References: <v03020902afe213ce5f4b @ [134 . 7 . 108 . 34]>
Reply-to: claudio @ DI . Unipi . IT

Bret Watson wrote:
> XNTPD can be set up to be safe.
> i. fully utilise the voting system - find at least 6 NTP servers
> (secondaries or above) that are geographically distant - I use one in
> france, in in Switzerland, one in Aust, one in NZ and one in Japan.
> ii. if you can get a DES library and rebuild XNTPD with it - there is a
> setting for it to use DES to authenticate - the auth is quite strong as it
> is effectively a one-time pad system. Most primaries will permit DES auth
> and some secondaries.
> 
> The first item makes it very hard to spoof the packets, the second makes it
> impossible.

Note that if somebody wants to attack you, it could first try to attack
your ISP. In this case, it could spoof all your NTP servers at the same
time, wherever they are.

I don't know the NTP authentication system, but probably it isn't a real
one time pad (probably it will eventually cicle).
It could nevertheless be an adequate protection.

ciao

- Claudio



Follow-Ups:
References:
Indexed By Date Previous: Remote Management
From: Clyde Williamson <clydew @ ee . net>
Next: Re: IP Filters?
From: Brian Mitchell <brian @ firehouse . net>
Indexed By Thread Previous: Re: need suggestion xntpd a security hole ???
From: "Neil D. Quiogue" <neil @ iphil . net>
Next: Re: need suggestion xntpd a security hole ???
From: Bret Watson <Bret . Watson @ bwa . net>

Google
 
Search Internet Search www.greatcircle.com