Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Open NTP Vulnerability letter

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service
Register FAQ Community Calendar

Open NTP Vulnerability letter
Reply
 
Thread Tools
Old 24-08-2014, 08:44   #1
UnStable
cf.member
 
Join Date: Oct 2006
Posts: 55
UnStable is an unknown quantity at this point
Open NTP Vulnerability letter

I received this yesterday, is it a generic letter they are sending out to everyone or are they targetting people identified as having this vulnerability?
I went to the website mentioned in the letter openntpproject.org but still really have no clue what it is I'm supposed to do
UnStable is offline   Reply With Quote
Advertisement
Old 24-08-2014, 09:54   #2
Sirius
Grumpy Fecker
 
Sirius's Avatar
 
Join Date: Jul 2007
Location: Warrington
Age: 64
Services: Every Weekend
Posts: 16,738
Sirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver bling
Sirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver bling
Re: Open NTP Vulnerability letter

Quote:
Originally Posted by UnStable View Post
I received this yesterday, is it a generic letter they are sending out to everyone or are they targetting people identified as having this vulnerability?
I went to the website mentioned in the letter openntpproject.org but still really have no clue what it is I'm supposed to do
I had one of those, found out it was my clearos router that had a ntp server running. Just turned the ntp server
off and never had another letter.
__________________
I stand with Ukraine

https://www.macmillan.org.uk/cancer-...bladder-cancer
Sirius is offline   Reply With Quote
Old 24-08-2014, 10:33   #3
General Maximus
Ran Away
 
Join Date: Nov 2008
Location: Lincoln
Services: phone + 1gbit BB + SkyQ
Posts: 11,021
General Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronze
General Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronze
Re: Open NTP Vulnerability letter

it is nice that VM are being proactive in their network security but I think they are digging themselves a hole.



The website they ask you to go to isn't particularly user friendly and they are sort of scaring customers into going to PC World (who are useless) and paying money to get it fixed.
General Maximus is offline   Reply With Quote
Old 25-08-2014, 10:13   #4
UnStable
cf.member
 
Join Date: Oct 2006
Posts: 55
UnStable is an unknown quantity at this point
Re: Open NTP Vulnerability letter

I have a Synology NAS and in the firewall settings for that I found an option to disable NTP Service on port 123 which I've now done.
I'm assuming this is what Virgin were referring to (or at least I hope so) and no I wouldn't go near the numpties at PC World to sort something like this out they wouldn't have a clue
UnStable is offline   Reply With Quote
Old 25-08-2014, 10:24   #5
General Maximus
Ran Away
 
Join Date: Nov 2008
Location: Lincoln
Services: phone + 1gbit BB + SkyQ
Posts: 11,021
General Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronze
General Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronze
Re: Open NTP Vulnerability letter

I would love to walk in and do a survey and see if any of them actually know what ntp is.
General Maximus is offline   Reply With Quote
Old 27-08-2014, 13:36   #6
jfish
Inactive
 
Join Date: Apr 2012
Posts: 52
jfish is on a distinguished roadjfish is on a distinguished road
Re: Open NTP Vulnerability letter

I assume this is sent out with the recent NTP amplification attack which generated around 400 Gbps traffic
jfish is offline   Reply With Quote
Old 27-08-2014, 17:01   #7
General Maximus
Ran Away
 
Join Date: Nov 2008
Location: Lincoln
Services: phone + 1gbit BB + SkyQ
Posts: 11,021
General Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronze
General Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronze
Re: Open NTP Vulnerability letter

lol, you just cant imagine having that amount of bandwidth at your fingertips.
General Maximus is offline   Reply With Quote
Old 27-08-2014, 23:44   #8
qasdfdsaq
cf.mega poster
 
Join Date: Aug 2004
Posts: 11,207
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
Re: Open NTP Vulnerability letter

It's really not that exciting.
qasdfdsaq is offline   Reply With Quote
Old 28-08-2014, 10:00   #9
horseman
cf.geek
 
horseman's Avatar
 
Join Date: Dec 2003
Location: Hove East sussex
Age: 73
Posts: 574
horseman has reached the bronze age
horseman has reached the bronze agehorseman has reached the bronze age
Re: Open NTP Vulnerability letter

Quote:
Originally Posted by UnStable View Post
I have a Synology NAS and in the firewall settings for that I found an option to disable NTP Service on port 123 which I've now done. ...
What DSM version are you running? CVE-2013-5211 should have been fixed back in one of the DSM 4.3 updates and of course DSM5.0.4493 update4 is also available if your DS model is comparable?
Synology (Amazon cloudfront CDN)website appears temporarily unavailable but worth checking release notes as NTP vulnerability is one of many if you're not up-to-date!
horseman is offline   Reply With Quote
Old 30-08-2014, 08:23   #10
UnStable
cf.member
 
Join Date: Oct 2006
Posts: 55
UnStable is an unknown quantity at this point
Re: Open NTP Vulnerability letter

Quote:
Originally Posted by horseman View Post
What DSM version are you running?
I have been on DSM5.0.4493 for a while and updated to update4 this week so not sure what else it could be if not the Synology box?
UnStable is offline   Reply With Quote
Old 30-08-2014, 12:28   #11
Qtx
CF's Worst Nightmare
 
Join Date: May 2012
Location: Probably outside the M25
Services: Sky Fibre Unlimited 40/10
Posts: 3,473
Qtx has a bronzed appealQtx has a bronzed appeal
Qtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appeal
Re: Open NTP Vulnerability letter

Are they sending out to everyone who just has an NTP server public facing or only the ones that are actually vulnerable to the monlist type issues? It's the initial question asked in this thread but still no answered and would help everyone to know the answer.
Qtx is offline   Reply With Quote
Old 30-08-2014, 12:41   #12
General Maximus
Ran Away
 
Join Date: Nov 2008
Location: Lincoln
Services: phone + 1gbit BB + SkyQ
Posts: 11,021
General Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronze
General Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronzeGeneral Maximus is cast in bronze
Re: Open NTP Vulnerability letter

the way the VM letter is worded it sounds like they have done a port scan and/or other tests and have only sent the letter out to those who are vulnerable.
General Maximus is offline   Reply With Quote
Old 30-08-2014, 13:14   #13
Qtx
CF's Worst Nightmare
 
Join Date: May 2012
Location: Probably outside the M25
Services: Sky Fibre Unlimited 40/10
Posts: 3,473
Qtx has a bronzed appealQtx has a bronzed appeal
Qtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appealQtx has a bronzed appeal
Re: Open NTP Vulnerability letter

Quote:
Originally Posted by General Maximus View Post
the way the VM letter is worded it sounds like they have done a port scan and/or other tests and have only sent the letter out to those who are vulnerable.
It does say vulnerable in the letter but I have seen similar letters in different arena's that have been based on nothing more than a port scan. Guess that's why i'm less trusting of these letters and on top of that, its VM
Qtx is offline   Reply With Quote
Old 30-08-2014, 22:21   #14
horseman
cf.geek
 
horseman's Avatar
 
Join Date: Dec 2003
Location: Hove East sussex
Age: 73
Posts: 574
horseman has reached the bronze age
horseman has reached the bronze agehorseman has reached the bronze age
Re: Open NTP Vulnerability letter

Quote:
Originally Posted by UnStable View Post
I have been on DSM5.0.4493 for a while and updated to update4 this week so not sure what else it could be if not the Synology box?
Same here on a DS411J and I haven't received any similar letters. The NTP reflection/amplification vulnerability was also fixed in 4.3 by Synology in March anyway.
DSM5 should already be corrected[**], so unless VM checked prior to March then you shouldn't be causing the problem from the Synology ntp server anyway[*]?

Quote:
Version: 4.3-3827 Update 1

(2014/3/18)

Change Log

Fixed a security issue related to OpenSSL (CVE-2013-4353).
Fixed security issues by upgrading PHP to version 5.3.28 (CVE-2013-4073, CVE-2013-6420).
Fixed a security issue to prevent malicious attacks via NTP service (CVE-2013-5211).
[*] You only need NTP server typically when running Surveillance station (or High Availabilty) options. Using the normal port123 to sync the NAS to an external NTP server is not the vulnerability.

[**] I SSH'd into my DSM5.0.4493-4 and checked ntpdc "monlist" which reassuringly didn't respond. However I note the build was compiled 29May2014 so perhaps if VM ran a check for open NTP servers prior to any DSM5 June build it might have flagged it?
horseman is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 12:49.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.