daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-ntp.md (15314B)


      1 ---
      2 title: "123/udp - Pentesting NTP"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-ntp.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-ntp.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 123/udp - Pentesting NTP
     14 
     15 ## Basic Information
     16 
     17 The **Network Time Protocol (NTP)** ensures computers and network devices across variable-latency networks sync their clocks accurately. It's vital for maintaining precise timekeeping in IT operations, security, and logging. Because time is used in nearly every authentication, crypto-protocol and forensic process, **an attacker that can influence NTP can often bypass security controls or make attacks harder to investigate.**
     18 
     19 ### Summary & Security Tips
     20 
     21 - **Purpose**: Syncs device clocks over networks.
     22 - **Importance**: Critical for security, logging, crypto-protocols and distributed systems.
     23 - **Security Measures**:
     24   - Use trusted NTP or NTS (Network Time Security) sources with authentication.
     25   - Restrict who can query/command the daemon (``restrict default noquery``, ``kod`` etc.).
     26   - Restrict Mode-6 (`ntpq`) and legacy Mode-7 (`ntpdc`/`monlist`) control queries or rate-limit them.
     27   - Monitor synchronization drift/leap-second state for tampering.
     28   - Keep the daemon updated (see recent CVEs below).
     29 
     30 **Default ports**
     31 
     32 ```text
     33 123/udp   NTP            (data + legacy control)
     34 323/udp   chronyd command/monitoring protocol (when remotely bound)
     35 4460/tcp  NTS-KE (RFC 8915) – TLS key-establishment for NTP
     36 ```
     37 
     38 ```text
     39 PORT    STATE SERVICE REASON
     40 123/udp open  ntp     udp-response
     41 ```
     42 
     43 ---
     44 ## Enumeration
     45 
     46 ### Classic ntpd control protocols (Mode 6/7)
     47 
     48 ```bash
     49 # Information & variables
     50 ntpq -c rv <IP>
     51 ntpq -c readvar <IP>
     52 ntpq -c peers <IP>
     53 ntpq -c associations <IP>
     54 
     55 # Legacy mode-7 (often disabled >=4.2.8p9)
     56 ntpdc -c monlist <IP>
     57 ntpdc -c listpeers <IP>
     58 ntpdc -c sysinfo  <IP>
     59 ```
     60 
     61 ### chrony / chronyc (UDP/323)
     62 
     63 `chronyc` does **not** send these commands to UDP/123: the default `chronyd` command port is **323/udp**. Remote access additionally requires a non-loopback `bindcmdaddress` and a matching `cmdallow`; chrony 4.7+ can further restrict exposed reports with `opencommands`. The `-a` switch seen in old examples is now ignored. Scan and query this surface separately.<sup>[[9]](#references)[[11]](#references)</sup>
     64 
     65 ```bash
     66 nmap -sU -sV -p 323 <IP>
     67 chronyc -n -h <IP> tracking
     68 chronyc -n -h <IP> sources -v
     69 chronyc -n -h <IP> sourcestats
     70 chronyc -n -h <IP> activity
     71 ```
     72 
     73 Only the configured monitoring commands are reachable over the network; commands which alter daemon state remain Unix-socket-only. Reports such as `sources`, `tracking`, `ntpdata`, `clients`, and `serverstats` can reveal upstream addresses, clock quality, client activity, and rate-limit state when an operator has exposed them.<sup>[[9]](#references)[[11]](#references)</sup>
     74 
     75 ### Nmap
     76 
     77 ```bash
     78 # Safe discovery & vuln detection
     79 nmap -sU -sV --script "ntp* and (discovery or vuln) and not (dos or brute)" -p 123 <IP>
     80 
     81 # Explicit monlist check
     82 nmap -sU -p123 --script ntp-monlist <IP>
     83 ```
     84 
     85 ### Mass/Internet scanning
     86 
     87 ```bash
     88 # Check if MONLIST is enabled (zgrab2 module)
     89 zgrab2 ntp --monlist --timeout 3 --output-file monlist.json -f "zmap_results.csv"
     90 ```
     91 
     92 ---
     93 ## Examine configuration files
     94 
     95 - ``/etc/ntp.conf`` (ntpd)
     96 - ``/etc/chrony/chrony.conf`` (chrony)
     97 - ``/etc/systemd/timesyncd.conf`` (timesyncd – client only)
     98 
     99 Pay special attention to ``restrict`` lines, ``kod`` (Kiss-o'-Death) settings, ``disable monitor``/``includefile /etc/ntp/crypto`` and whether *NTS* is enabled (``nts enable``). For chrony, audit `bindcmdaddress`, `cmdport`, `cmdallow`/`cmddeny`, `opencommands`, and `cmdratelimit`; `allow` controls NTP clients and is independent from `cmdallow`.<sup>[[11]](#references)</sup>
    100 
    101 ---
    102 ## Selected Vulnerabilities and Operational Risks
    103 
    104 | Year | CVE | Component | Impact |
    105 |------|-----|-----------|--------|
    106 | 2023 | **CVE-2023-26551 through CVE-2023-26555** | ntp 4.2.8p15 and earlier | Several low-severity parsing and bounds-checking flaws fixed in **4.2.8p16**; upgrade or back-port the vendor fixes.<sup>[[5]](#references)</sup> |
    107 | 2023 | **CVE-2023-33192** | **ntpd-rs** (Rust implementation) | Malformed **NTS** cookie causes remote **DoS** prior to v0.3.3 – affects port 123 even when NTS **disabled**.<sup>[[6]](#references)</sup> |
    108 | 2024 | distro updates | **chrony 4.4 / 4.5** – several security hardening & NTS-KE fixes (e.g. SUSE-RU-2024:2022)<sup>[[7]](#references)</sup> |
    109 | 2025 | **CVE-2025-58066** | **ntpd-rs 1.2.0–1.6.1**, server mode | A response/request validation error can turn two exposed servers into a persistent packet loop; fixed in 1.6.2.<sup>[[14]](#references)</sup> |
    110 | 2014 | NTP reflection at scale | Cloudflare documented a **400 Gbps NTP amplification** attack that abused exposed `monlist` responders. Keep monitoring queries inaccessible from untrusted networks.<sup>[[3]](#references)</sup> |
    111 
    112 The 2023 ntp.org group contains two distinct attack surfaces. **CVE-2023-26551 through CVE-2023-26554** are out-of-bounds writes in `libntp/mstolfp.c`; their records describe a malicious server attacking the **client-side `ntpq` process**, not `ntpd`. **CVE-2023-26555** affects `praecis_parse()` in the Palisade reference-clock driver and requires a more specialized input path, such as a manipulated GPS receiver.<sup>[[5]](#references)[[12]](#references)[[13]](#references)</sup>
    113 
    114 > **Operator exposure:** Because CVE-2023-26551 through CVE-2023-26554 are client-side `ntpq` parsing flaws, querying an untrusted or attacker-controlled NTP server is the dangerous direction. Avoid pointing an unpatched diagnostic client at arbitrary Internet hosts; use **4.2.8p16** or a vendor-backported fix.<sup>[[5]](#references)[[12]](#references)</sup>
    115 
    116 ---
    117 ## Advanced Attacks
    118 
    119 ### 1. NTP Amplification / Reflection
    120 
    121 The legacy Mode-7 `monlist` query can return information about up to **600 recent clients**. A small spoofed request can therefore trigger a much larger multi-packet response, producing amplification factors in the hundreds in vulnerable configurations.<sup>[[3]](#references)[[4]](#references)</sup> Mitigations:
    122 
    123 - Upgrade to a supported release (at least **4.2.8p16** for the 2023 fixes) and **add** `disable monitor` where legacy monitoring is unnecessary.
    124 - Rate-limit UDP/123 on the edge or enable *sessions-required* on DDoS appliances.
    125 - Enable *BCP 38* egress filtering to block source spoofing.
    126 
    127 See Cloudflare’s learning-center article for a step-by-step breakdown.<sup>[[4]](#references)</sup> 
    128 
    129 ### 2. Time-Shift / Delay attacks (Khronos / Chronos research)
    130 
    131 Even with authentication, an on-path attacker can attempt to **shift the client clock** by dropping or delaying packets. RFC 9523's **Khronos** mechanism queries a large, diverse server pool and periodically applies a robust selection algorithm to resist time-shifting attacks.<sup>[[8]](#references)</sup> Chrony's `maxdistance`, `maxjitter`, and `minsources` controls are useful source-selection safeguards, but they are configuration controls rather than an implementation of Khronos.<sup>[[11]](#references)</sup>
    132 
    133 ### 3. NTS abuse & 4460/tcp exposure
    134 
    135 NTS moves the heavy crypto to a separate **TLS 1.3 channel on 4460/tcp** (``ntske/1``). Poor implementations (see CVE-2023-33192) crash when parsing cookies or allow weak ciphers. Pentesters should:
    136 
    137 ```bash
    138 # TLS reconnaissance
    139 nmap -sV -p 4460 --script ssl-enum-ciphers,ssl-cert <IP>
    140 
    141 # Grab banner & ALPN
    142 openssl s_client -connect <IP>:4460 -alpn ntske/1 -tls1_3 -ign_eof
    143 ```
    144 
    145 Look for certificate-validation failures, unexpected trust anchors, missing `ntske/1` ALPN negotiation, and implementation-specific parsing failures. RFC 8915 requires TLS 1.3 or later for NTS-KE and separately negotiates an AEAD algorithm for protected NTP packets.<sup>[[1]](#references)</sup>
    146 
    147 ### 4. Response-loop / message-storm DoS
    148 
    149 Do not assume that every packet received on UDP/123 is a client request. In ntpd-rs 1.2.0 through 1.6.1, a server replied even to **server response** packets. An attacker able to spoof the address of exposed server B in one such packet to server A could make A and B continuously reply to each other. This is a distinct primitive from amplification: the initial spoofed packet creates a self-sustaining two-node loop.<sup>[[14]](#references)</sup>
    150 
    151 Treat active validation as disruptive. In an authorized lab, first inventory versions/configuration and watch for alternating UDP/123 traffic which continues without client requests:
    152 
    153 ```bash
    154 sudo tcpdump -ni any 'udp port 123 and (host <SERVER_A> or host <SERVER_B>)'
    155 ```
    156 
    157 The vulnerable range applies only when ntpd-rs is acting as a server and accepts non-NTS traffic. Upgrade to **1.6.2+**; when patching is delayed, restrict clients and discard non-request NTP modes at the edge.<sup>[[14]](#references)</sup>
    158 
    159 ### 5. Malicious pool servers and zone monopolization
    160 
    161 Authentication protects packet origin and integrity, but it cannot make a deliberately malicious time server truthful. A 2026 measurement study found that only **19.7%** of active NTP Pool servers were fully independent after grouping aliases, accounts, and network connectivity. Its capacity-informed model and ethical validation showed that **90% of country zones** could have at least half of their pool traffic captured with ten or fewer maximum-capacity server registrations.<sup>[[15]](#references)</sup>
    162 
    163 Useful attacker primitives include cheap IPv6 aliases, declaring high `netspeed`, learning pool monitors while in monitor-only mode, returning correct time selectively to those monitors, and later skewing ordinary clients. Residual queries can also continue long after a server is removed because some clients retain its address. During an assessment, therefore, resolve pool names repeatedly from multiple vantage points and group answers by operator/account where known, ASN, prefix, physical alias, and IP family—four addresses are not four independent trust domains.<sup>[[15]](#references)</sup>
    164 
    165 For critical clients, prefer pinned, independently administered NTS servers rather than relying on multiple names from one pool or provider. Diversity must include administrative and network-path diversity, not only address count.<sup>[[1]](#references)[[15]](#references)</sup>
    166 
    167 ---
    168 ## Hardening / Best-Current-Practice (BCP-233 / RFC 8633)
    169 
    170 *Operators SHOULD:*
    171 
    172 1. Use **≥ 4** independent, diverse time sources (public pools, GPS, PTP-bridges) to avoid single-source poisoning; several IPs behind one operator, ASN, or pool account are correlated sources.<sup>[[15]](#references)</sup>
    173 2. Enable ``kod`` and ``limited``/``nomodify`` restrictions so abusive clients receive **Kiss-o'-Death** rate-limit packets instead of full responses.
    174 3. Monitor daemon logs for **panic** events or step adjustments > 1000 s. (Signatures of attack per RFC 8633 §5.3.)
    175 4. Consider **leap-smear** to avoid leap-second outages, but ensure *all* downstream clients use the same smear window.
    176 5. Keep polling ≤24 h so leap-second flags are not missed.
    177 6. Keep `chronyd` command access on loopback where possible. Otherwise firewall UDP/323, narrowly scope `cmdallow`, expose only required `opencommands`, and retain `cmdratelimit`.<sup>[[11]](#references)</sup>
    178 
    179 See RFC 8633 for a comprehensive checklist.<sup>[[2]](#references)</sup> 
    180 
    181 ---
    182 ## Shodan / Censys Dorks
    183 
    184 ```text
    185 port:123 "ntpd"          # Version banner
    186 udp port:123 monlist:true # Censys tag for vulnerable servers
    187 port:4460 "ntske"         # NTS-KE
    188 ```
    189 
    190 ---
    191 ## Useful Tools
    192 
    193 | Tool | Purpose | Example |
    194 |------|---------|---------|
    195 | **zgrab2 ntp** | Mass scanning / JSON output including monlist flag<sup>[[10]](#references)</sup> | See command above |
    196 | `chronyd` with `local` + `allow` | Run a controlled NTP server in a pentest lab | See configuration below |
    197 | Packet-crafting frameworks | Build or replay NTP packets in an authorized lab after establishing an on-path position | Validate the packet fields and timing effect with a capture |
    198 
    199 `chronyd -q` sets the local clock once and exits; it does **not** create a test server. A minimal isolated-lab server can instead be started with:<sup>[[11]](#references)</sup>
    200 
    201 ```bash
    202 cat >/tmp/chrony-lab.conf <<'EOF'
    203 local stratum 8
    204 allow 192.0.2.0/24
    205 bindaddress 192.0.2.10
    206 EOF
    207 sudo chronyd -d -f /tmp/chrony-lab.conf
    208 ```
    209 
    210 ---
    211 ## HackTricks Automatic Commands
    212 
    213 ```text
    214 Protocol_Name: NTP
    215 Port_Number: 123
    216 Protocol_Description: Network Time Protocol
    217 
    218 Entry_1:
    219   Name: Notes
    220   Description: Notes for NTP
    221   Note: |
    222     The Network Time Protocol (NTP) ensures computers and network devices across variable-latency networks sync their clocks accurately. It's vital for maintaining precise timekeeping in IT operations, security, and logging. NTP's accuracy is essential, but it also poses security risks if not properly managed.
    223 
    224     https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-ntp.html
    225 
    226 Entry_2:
    227   Name: Nmap
    228   Description: Enumerate NTP
    229   Command: nmap -sU -sV --script "ntp* and (discovery or vuln) and not (dos or brute)" -p 123 {IP}
    230 ```
    231 
    232 ---
    233 
    234 
    235 ## References
    236 
    237 - [1] [RFC 8915 – Network Time Security for the Network Time Protocol (port 4460)](https://www.rfc-editor.org/rfc/rfc8915)
    238 - [2] [RFC 8633 – Network Time Protocol BCP](https://www.rfc-editor.org/rfc/rfc8633)
    239 - [3] [Cloudflare – Technical Details Behind a 400 Gbps NTP Amplification DDoS Attack](https://blog.cloudflare.com/technical-details-behind-a-400gbps-ntp-amplification-ddos-attack/)
    240 - [4] [Cloudflare Learning Center – NTP Amplification DDoS Attack](https://www.cloudflare.com/learning/ddos/ntp-amplification-ddos-attack/)
    241 - [5] [NTP Project – ntp-4.2.8 series changelog](https://www.ntp.org/support/securitynotice/4_2_8-series-changelog/)
    242 - [6] [NVD – CVE-2023-33192 (ntpd-rs NTS cookie denial of service)](https://nvd.nist.gov/vuln/detail/CVE-2023-33192)
    243 - [7] [SUSE – Recommended update for chrony (SUSE-RU-2024:2022-1)](https://www.suse.com/support/update/announcement/2024/suse-ru-20242022-1/)
    244 - [8] [RFC 9523 – A Secure Selection and Filtering Mechanism for the Network Time Protocol with Khronos](https://www.rfc-editor.org/rfc/rfc9523)
    245 - [9] [chrony project – chronyc(1) manual](https://chrony-project.org/doc/4.9/chronyc.html)
    246 - [10] [zgrab2 – ntp module](https://github.com/zmap/zgrab2/tree/master/modules/ntp)
    247 - [11] [chrony project – chrony.conf(5) configuration manual](https://chrony-project.org/doc/4.9/chrony.conf.html)
    248 - [12] [CVE.org - CVE-2023-26551 (`mstolfp` out-of-bounds write)](https://www.cve.org/CVERecord?id=CVE-2023-26551)
    249 - [13] [CVE.org - CVE-2023-26555 (`praecis_parse` out-of-bounds write)](https://www.cve.org/CVERecord?id=CVE-2023-26555)
    250 - [14] [ntpd-rs advisory – response-loop denial of service (GHSA-4855-q42w-5vr4)](https://github.com/pendulum-project/ntpd-rs/security/advisories/GHSA-4855-q42w-5vr4)
    251 - [15] [NDSS 2026 – On Borrowed Time: Measurement-Informed Understanding of the NTP Pool's Robustness to Monopoly Attacks](https://www.ndss-symposium.org/wp-content/uploads/2026-f541-paper.pdf)