pentesting-ntp.md (15314B)
1 --- 2 title: "123/udp - Pentesting NTP" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-ntp.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-ntp.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 123/udp - Pentesting NTP 14 15 ## Basic Information 16 17 The **Network Time Protocol (NTP)** ensures computers and network devices across variable-latency networks sync their clocks accurately. It's vital for maintaining precise timekeeping in IT operations, security, and logging. Because time is used in nearly every authentication, crypto-protocol and forensic process, **an attacker that can influence NTP can often bypass security controls or make attacks harder to investigate.** 18 19 ### Summary & Security Tips 20 21 - **Purpose**: Syncs device clocks over networks. 22 - **Importance**: Critical for security, logging, crypto-protocols and distributed systems. 23 - **Security Measures**: 24 - Use trusted NTP or NTS (Network Time Security) sources with authentication. 25 - Restrict who can query/command the daemon (``restrict default noquery``, ``kod`` etc.). 26 - Restrict Mode-6 (`ntpq`) and legacy Mode-7 (`ntpdc`/`monlist`) control queries or rate-limit them. 27 - Monitor synchronization drift/leap-second state for tampering. 28 - Keep the daemon updated (see recent CVEs below). 29 30 **Default ports** 31 32 ```text 33 123/udp NTP (data + legacy control) 34 323/udp chronyd command/monitoring protocol (when remotely bound) 35 4460/tcp NTS-KE (RFC 8915) – TLS key-establishment for NTP 36 ``` 37 38 ```text 39 PORT STATE SERVICE REASON 40 123/udp open ntp udp-response 41 ``` 42 43 --- 44 ## Enumeration 45 46 ### Classic ntpd control protocols (Mode 6/7) 47 48 ```bash 49 # Information & variables 50 ntpq -c rv <IP> 51 ntpq -c readvar <IP> 52 ntpq -c peers <IP> 53 ntpq -c associations <IP> 54 55 # Legacy mode-7 (often disabled >=4.2.8p9) 56 ntpdc -c monlist <IP> 57 ntpdc -c listpeers <IP> 58 ntpdc -c sysinfo <IP> 59 ``` 60 61 ### chrony / chronyc (UDP/323) 62 63 `chronyc` does **not** send these commands to UDP/123: the default `chronyd` command port is **323/udp**. Remote access additionally requires a non-loopback `bindcmdaddress` and a matching `cmdallow`; chrony 4.7+ can further restrict exposed reports with `opencommands`. The `-a` switch seen in old examples is now ignored. Scan and query this surface separately.<sup>[[9]](#references)[[11]](#references)</sup> 64 65 ```bash 66 nmap -sU -sV -p 323 <IP> 67 chronyc -n -h <IP> tracking 68 chronyc -n -h <IP> sources -v 69 chronyc -n -h <IP> sourcestats 70 chronyc -n -h <IP> activity 71 ``` 72 73 Only the configured monitoring commands are reachable over the network; commands which alter daemon state remain Unix-socket-only. Reports such as `sources`, `tracking`, `ntpdata`, `clients`, and `serverstats` can reveal upstream addresses, clock quality, client activity, and rate-limit state when an operator has exposed them.<sup>[[9]](#references)[[11]](#references)</sup> 74 75 ### Nmap 76 77 ```bash 78 # Safe discovery & vuln detection 79 nmap -sU -sV --script "ntp* and (discovery or vuln) and not (dos or brute)" -p 123 <IP> 80 81 # Explicit monlist check 82 nmap -sU -p123 --script ntp-monlist <IP> 83 ``` 84 85 ### Mass/Internet scanning 86 87 ```bash 88 # Check if MONLIST is enabled (zgrab2 module) 89 zgrab2 ntp --monlist --timeout 3 --output-file monlist.json -f "zmap_results.csv" 90 ``` 91 92 --- 93 ## Examine configuration files 94 95 - ``/etc/ntp.conf`` (ntpd) 96 - ``/etc/chrony/chrony.conf`` (chrony) 97 - ``/etc/systemd/timesyncd.conf`` (timesyncd – client only) 98 99 Pay special attention to ``restrict`` lines, ``kod`` (Kiss-o'-Death) settings, ``disable monitor``/``includefile /etc/ntp/crypto`` and whether *NTS* is enabled (``nts enable``). For chrony, audit `bindcmdaddress`, `cmdport`, `cmdallow`/`cmddeny`, `opencommands`, and `cmdratelimit`; `allow` controls NTP clients and is independent from `cmdallow`.<sup>[[11]](#references)</sup> 100 101 --- 102 ## Selected Vulnerabilities and Operational Risks 103 104 | Year | CVE | Component | Impact | 105 |------|-----|-----------|--------| 106 | 2023 | **CVE-2023-26551 through CVE-2023-26555** | ntp 4.2.8p15 and earlier | Several low-severity parsing and bounds-checking flaws fixed in **4.2.8p16**; upgrade or back-port the vendor fixes.<sup>[[5]](#references)</sup> | 107 | 2023 | **CVE-2023-33192** | **ntpd-rs** (Rust implementation) | Malformed **NTS** cookie causes remote **DoS** prior to v0.3.3 – affects port 123 even when NTS **disabled**.<sup>[[6]](#references)</sup> | 108 | 2024 | distro updates | **chrony 4.4 / 4.5** – several security hardening & NTS-KE fixes (e.g. SUSE-RU-2024:2022)<sup>[[7]](#references)</sup> | 109 | 2025 | **CVE-2025-58066** | **ntpd-rs 1.2.0–1.6.1**, server mode | A response/request validation error can turn two exposed servers into a persistent packet loop; fixed in 1.6.2.<sup>[[14]](#references)</sup> | 110 | 2014 | NTP reflection at scale | Cloudflare documented a **400 Gbps NTP amplification** attack that abused exposed `monlist` responders. Keep monitoring queries inaccessible from untrusted networks.<sup>[[3]](#references)</sup> | 111 112 The 2023 ntp.org group contains two distinct attack surfaces. **CVE-2023-26551 through CVE-2023-26554** are out-of-bounds writes in `libntp/mstolfp.c`; their records describe a malicious server attacking the **client-side `ntpq` process**, not `ntpd`. **CVE-2023-26555** affects `praecis_parse()` in the Palisade reference-clock driver and requires a more specialized input path, such as a manipulated GPS receiver.<sup>[[5]](#references)[[12]](#references)[[13]](#references)</sup> 113 114 > **Operator exposure:** Because CVE-2023-26551 through CVE-2023-26554 are client-side `ntpq` parsing flaws, querying an untrusted or attacker-controlled NTP server is the dangerous direction. Avoid pointing an unpatched diagnostic client at arbitrary Internet hosts; use **4.2.8p16** or a vendor-backported fix.<sup>[[5]](#references)[[12]](#references)</sup> 115 116 --- 117 ## Advanced Attacks 118 119 ### 1. NTP Amplification / Reflection 120 121 The legacy Mode-7 `monlist` query can return information about up to **600 recent clients**. A small spoofed request can therefore trigger a much larger multi-packet response, producing amplification factors in the hundreds in vulnerable configurations.<sup>[[3]](#references)[[4]](#references)</sup> Mitigations: 122 123 - Upgrade to a supported release (at least **4.2.8p16** for the 2023 fixes) and **add** `disable monitor` where legacy monitoring is unnecessary. 124 - Rate-limit UDP/123 on the edge or enable *sessions-required* on DDoS appliances. 125 - Enable *BCP 38* egress filtering to block source spoofing. 126 127 See Cloudflare’s learning-center article for a step-by-step breakdown.<sup>[[4]](#references)</sup> 128 129 ### 2. Time-Shift / Delay attacks (Khronos / Chronos research) 130 131 Even with authentication, an on-path attacker can attempt to **shift the client clock** by dropping or delaying packets. RFC 9523's **Khronos** mechanism queries a large, diverse server pool and periodically applies a robust selection algorithm to resist time-shifting attacks.<sup>[[8]](#references)</sup> Chrony's `maxdistance`, `maxjitter`, and `minsources` controls are useful source-selection safeguards, but they are configuration controls rather than an implementation of Khronos.<sup>[[11]](#references)</sup> 132 133 ### 3. NTS abuse & 4460/tcp exposure 134 135 NTS moves the heavy crypto to a separate **TLS 1.3 channel on 4460/tcp** (``ntske/1``). Poor implementations (see CVE-2023-33192) crash when parsing cookies or allow weak ciphers. Pentesters should: 136 137 ```bash 138 # TLS reconnaissance 139 nmap -sV -p 4460 --script ssl-enum-ciphers,ssl-cert <IP> 140 141 # Grab banner & ALPN 142 openssl s_client -connect <IP>:4460 -alpn ntske/1 -tls1_3 -ign_eof 143 ``` 144 145 Look for certificate-validation failures, unexpected trust anchors, missing `ntske/1` ALPN negotiation, and implementation-specific parsing failures. RFC 8915 requires TLS 1.3 or later for NTS-KE and separately negotiates an AEAD algorithm for protected NTP packets.<sup>[[1]](#references)</sup> 146 147 ### 4. Response-loop / message-storm DoS 148 149 Do not assume that every packet received on UDP/123 is a client request. In ntpd-rs 1.2.0 through 1.6.1, a server replied even to **server response** packets. An attacker able to spoof the address of exposed server B in one such packet to server A could make A and B continuously reply to each other. This is a distinct primitive from amplification: the initial spoofed packet creates a self-sustaining two-node loop.<sup>[[14]](#references)</sup> 150 151 Treat active validation as disruptive. In an authorized lab, first inventory versions/configuration and watch for alternating UDP/123 traffic which continues without client requests: 152 153 ```bash 154 sudo tcpdump -ni any 'udp port 123 and (host <SERVER_A> or host <SERVER_B>)' 155 ``` 156 157 The vulnerable range applies only when ntpd-rs is acting as a server and accepts non-NTS traffic. Upgrade to **1.6.2+**; when patching is delayed, restrict clients and discard non-request NTP modes at the edge.<sup>[[14]](#references)</sup> 158 159 ### 5. Malicious pool servers and zone monopolization 160 161 Authentication protects packet origin and integrity, but it cannot make a deliberately malicious time server truthful. A 2026 measurement study found that only **19.7%** of active NTP Pool servers were fully independent after grouping aliases, accounts, and network connectivity. Its capacity-informed model and ethical validation showed that **90% of country zones** could have at least half of their pool traffic captured with ten or fewer maximum-capacity server registrations.<sup>[[15]](#references)</sup> 162 163 Useful attacker primitives include cheap IPv6 aliases, declaring high `netspeed`, learning pool monitors while in monitor-only mode, returning correct time selectively to those monitors, and later skewing ordinary clients. Residual queries can also continue long after a server is removed because some clients retain its address. During an assessment, therefore, resolve pool names repeatedly from multiple vantage points and group answers by operator/account where known, ASN, prefix, physical alias, and IP family—four addresses are not four independent trust domains.<sup>[[15]](#references)</sup> 164 165 For critical clients, prefer pinned, independently administered NTS servers rather than relying on multiple names from one pool or provider. Diversity must include administrative and network-path diversity, not only address count.<sup>[[1]](#references)[[15]](#references)</sup> 166 167 --- 168 ## Hardening / Best-Current-Practice (BCP-233 / RFC 8633) 169 170 *Operators SHOULD:* 171 172 1. Use **≥ 4** independent, diverse time sources (public pools, GPS, PTP-bridges) to avoid single-source poisoning; several IPs behind one operator, ASN, or pool account are correlated sources.<sup>[[15]](#references)</sup> 173 2. Enable ``kod`` and ``limited``/``nomodify`` restrictions so abusive clients receive **Kiss-o'-Death** rate-limit packets instead of full responses. 174 3. Monitor daemon logs for **panic** events or step adjustments > 1000 s. (Signatures of attack per RFC 8633 §5.3.) 175 4. Consider **leap-smear** to avoid leap-second outages, but ensure *all* downstream clients use the same smear window. 176 5. Keep polling ≤24 h so leap-second flags are not missed. 177 6. Keep `chronyd` command access on loopback where possible. Otherwise firewall UDP/323, narrowly scope `cmdallow`, expose only required `opencommands`, and retain `cmdratelimit`.<sup>[[11]](#references)</sup> 178 179 See RFC 8633 for a comprehensive checklist.<sup>[[2]](#references)</sup> 180 181 --- 182 ## Shodan / Censys Dorks 183 184 ```text 185 port:123 "ntpd" # Version banner 186 udp port:123 monlist:true # Censys tag for vulnerable servers 187 port:4460 "ntske" # NTS-KE 188 ``` 189 190 --- 191 ## Useful Tools 192 193 | Tool | Purpose | Example | 194 |------|---------|---------| 195 | **zgrab2 ntp** | Mass scanning / JSON output including monlist flag<sup>[[10]](#references)</sup> | See command above | 196 | `chronyd` with `local` + `allow` | Run a controlled NTP server in a pentest lab | See configuration below | 197 | Packet-crafting frameworks | Build or replay NTP packets in an authorized lab after establishing an on-path position | Validate the packet fields and timing effect with a capture | 198 199 `chronyd -q` sets the local clock once and exits; it does **not** create a test server. A minimal isolated-lab server can instead be started with:<sup>[[11]](#references)</sup> 200 201 ```bash 202 cat >/tmp/chrony-lab.conf <<'EOF' 203 local stratum 8 204 allow 192.0.2.0/24 205 bindaddress 192.0.2.10 206 EOF 207 sudo chronyd -d -f /tmp/chrony-lab.conf 208 ``` 209 210 --- 211 ## HackTricks Automatic Commands 212 213 ```text 214 Protocol_Name: NTP 215 Port_Number: 123 216 Protocol_Description: Network Time Protocol 217 218 Entry_1: 219 Name: Notes 220 Description: Notes for NTP 221 Note: | 222 The Network Time Protocol (NTP) ensures computers and network devices across variable-latency networks sync their clocks accurately. It's vital for maintaining precise timekeeping in IT operations, security, and logging. NTP's accuracy is essential, but it also poses security risks if not properly managed. 223 224 https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-ntp.html 225 226 Entry_2: 227 Name: Nmap 228 Description: Enumerate NTP 229 Command: nmap -sU -sV --script "ntp* and (discovery or vuln) and not (dos or brute)" -p 123 {IP} 230 ``` 231 232 --- 233 234 235 ## References 236 237 - [1] [RFC 8915 – Network Time Security for the Network Time Protocol (port 4460)](https://www.rfc-editor.org/rfc/rfc8915) 238 - [2] [RFC 8633 – Network Time Protocol BCP](https://www.rfc-editor.org/rfc/rfc8633) 239 - [3] [Cloudflare – Technical Details Behind a 400 Gbps NTP Amplification DDoS Attack](https://blog.cloudflare.com/technical-details-behind-a-400gbps-ntp-amplification-ddos-attack/) 240 - [4] [Cloudflare Learning Center – NTP Amplification DDoS Attack](https://www.cloudflare.com/learning/ddos/ntp-amplification-ddos-attack/) 241 - [5] [NTP Project – ntp-4.2.8 series changelog](https://www.ntp.org/support/securitynotice/4_2_8-series-changelog/) 242 - [6] [NVD – CVE-2023-33192 (ntpd-rs NTS cookie denial of service)](https://nvd.nist.gov/vuln/detail/CVE-2023-33192) 243 - [7] [SUSE – Recommended update for chrony (SUSE-RU-2024:2022-1)](https://www.suse.com/support/update/announcement/2024/suse-ru-20242022-1/) 244 - [8] [RFC 9523 – A Secure Selection and Filtering Mechanism for the Network Time Protocol with Khronos](https://www.rfc-editor.org/rfc/rfc9523) 245 - [9] [chrony project – chronyc(1) manual](https://chrony-project.org/doc/4.9/chronyc.html) 246 - [10] [zgrab2 – ntp module](https://github.com/zmap/zgrab2/tree/master/modules/ntp) 247 - [11] [chrony project – chrony.conf(5) configuration manual](https://chrony-project.org/doc/4.9/chrony.conf.html) 248 - [12] [CVE.org - CVE-2023-26551 (`mstolfp` out-of-bounds write)](https://www.cve.org/CVERecord?id=CVE-2023-26551) 249 - [13] [CVE.org - CVE-2023-26555 (`praecis_parse` out-of-bounds write)](https://www.cve.org/CVERecord?id=CVE-2023-26555) 250 - [14] [ntpd-rs advisory – response-loop denial of service (GHSA-4855-q42w-5vr4)](https://github.com/pendulum-project/ntpd-rs/security/advisories/GHSA-4855-q42w-5vr4) 251 - [15] [NDSS 2026 – On Borrowed Time: Measurement-Informed Understanding of the NTP Pool's Robustness to Monopoly Attacks](https://www.ndss-symposium.org/wp-content/uploads/2026-f541-paper.pdf)