Eight NTP vulnerabilities are detected during network time synchronization.

Source: Internet
Author: User

Eight NTP vulnerabilities are detected during network time synchronization.

Recently, Cisco researchers found eight security vulnerabilities in the Network Time Protocol (NTP). Currently, Linux, Mac, and BSD operating systems are using this Protocol. The time when these vulnerabilities were discovered happened to be the time Michael J. Fox traveled in the movie "back to future 2.

One of the eight Security Vulnerabilities allows hackers to manipulate the target clock, and the affected people believe that they have crossed the Future (it is a bit of an story ).

These vulnerabilities affect the NTP protocol daemon, which is a protocol for synchronizing time in the entire computer network (the computer network here can be the Internet, Intranet, or a smaller LAN ).

These vulnerabilities contain a logic error that allows hackers to bypass certificates and modify the local system time; memory crash: Enable protocol-caused buffer overflow or use (use-after-free) attacks; destroy the daemon or enable it to enter an endless loop, resulting in DoS status; directory traversal and file overwrite, allows hackers to overwrite NTPD configurations.

NTP 4.2.5p186 to 4.2.8p3 versions are affected. However, the NTP protocol developer released a new version yesterday to fix the above problems.

CentOS NTP server installation and configuration

NTP servers in Linux

NTP client configurations for multiple operating systems

Build an enterprise-level NTP Time Server

Set up an ntp time synchronization server in Linux

Enable NTP time server in CentOS 6.3

This article permanently updates the link address:

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.