iTnews

Opinion: Don't be an accidental vandal

By Nick Barron, on Aug 14, 2006 2:44PM
Opinion: Don't be an accidental vandal

In 2005, the operator of one of the top-level Network Time Protocol (NTP) time servers in Denmark noticed that a large volume of requests hitting his server were invalid.

The NTP is one of those very useful and often ignored internet services that lets you keep the clocks of all your machines in sync. Synchronized clocks make log analysis much more straightforward, so a good clock is essential for security services.

Anyway, back to the story. It turned out that the suspect requests were all using an old and deprecated version of the protocol. And there were a lot of them: more than three million connections from over 250,000 different machines. Smelling a rat, the operator decided to investigate further.

After a bit of detective work, he discovered that most, if not all, of the requests were coming from a particular model of wireless router used by home users and small businesses. In its default configuration, the router had the Denmark NTP server as one of its list of servers to contact.

Unfortunately the router's software broke several rules. First, it should not have been set to contact a so-called "Stratum 1" NTP server, which is reserved for larger networks. Second, to make matters worse, it made no attempt to cache the DNS lookups, so like an impatient child on a long drive it kept asking the same question over and over. Finally, and perhaps daftest of all, it attempted to synchronise the time every 30 seconds.

Of course the owners of the offending routers were none the wiser. As can be seen by the large number of unprotected wireless networks still around, Joe Public will usually not change default settings (nor should he have to, if the product has been sensibly configured). In effect, the routers were acting as a dumb, but large-scale denial-of-service attack. This is all rather frustrating, as a brief review of the relevant specifications will quickly identify the polite way of using services such as NTP.

This case shows once again why monitoring what is going out of your network is as important as knowing what's coming in. Unfortunately, many small business firewalls come pre-configured to assume that anything inside the wall is trustworthy, and allow anything to go out. This is a bit like setting up your plumbing to flush into the street.

A sensible security policy that limits outgoing connections to appropriate systems will prevent you from falling foul of badly configured hardware. There are enough intentional vandals on the internet, the last thing we need is accidental ones as well.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
accidentalanbedontopinionsecurityvandal

Partner Content

Top 5 Benefits of Managed IT Services
Promoted Content Top 5 Benefits of Managed IT Services
5 essential digital transformation ideas
Promoted Content 5 essential digital transformation ideas
"We're seeing some good policy put in place, but that's the exception"
Partner Content "We're seeing some good policy put in place, but that's the exception"
Avoiding CAPEX by making on-premise IT more cloud-like
Promoted Content Avoiding CAPEX by making on-premise IT more cloud-like

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Nick Barron,
Aug 14 2006
2:44PM
0 Comments

Related Articles

  • PEXA buys into AI fintech Elula
  • WA gov creates cyber security uplift team
  • Healthscope CISO heads to KPMG
  • Edtech vendors invaded student privacy: Human Rights Watch
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co to cut 160 applications under $200m IT simplification

NBN Co to cut 160 applications under $200m IT simplification

What to expect from the incoming Labor government

What to expect from the incoming Labor government

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co's 250Mbps and gigabit growth is finally clear

Digital Nation

Why do DeFi and DAOs matter to business?
Why do DeFi and DAOs matter to business?
COVER STORY: A Year in the Metaverse
COVER STORY: A Year in the Metaverse
COVER STORY: Data and IoT set digital agriculture on a sustainable future
COVER STORY: Data and IoT set digital agriculture on a sustainable future
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
Lendlease launches its own metaverse in Milan
Lendlease launches its own metaverse in Milan
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.