Date: Sat, 14 Jun 2003 04:34:11 -0500
From: Dave Plonka <plonka@localdomain>
To: abuse@[remotedomain]
Subject: sntp/ntp query flood from 10.42.69.10 to ntp1.cs.wisc.edu
[Organization] network abuse folks,
Since May 14, 2003 ~0800 central time, one of our campus' NTP
servers "ntp1.cs.wisc.edu" (128.105.39.11) has been the recipient of a
large-scale flood of Simple Network Time Protocol (SNTP) requests -
much more than it can service. This dramatic increase in inbound SNTP
requests inexplicably continues even now. To mitigate this flood we
are currently blocking over over 250K pkts/sec, exceeding 150
megabits/sec, and it has been continuing for weeks.
We are in the process of trying to determine if this flood is potentially
malicious or if it is an SNTP client misconfiguration or bug.
This traffic primarily consists of 76-byte UDP packets that are SNTP
version 1 queries from very many source host addresses directed to
ntp1.cs.wisc.edu port 123 (NTP). Unusually, these requests all have a
UDP source port of 23457. We have identified the host address
10.42.69.10 as just one of the sources. (However, there are at
least tens of thousands of source host addresses.)
I have attached a timestamped log of a packet capture from the
afternoon of June 13, 2003 (Friday) evidencing the SNTP query packets
from the host 10.42.69.10 at an unusually high rate of about one
per second. A packet decomposition (by tethereal) and hex dump of the
last packet (frame 998) in the log is included as well, which shows
them to be valid SNTP v1 queries as described in RFC 1361,
http://www.ietf.org/rfc/rfc1361.txt.
Could you assist us ASAP with this investigation by identifying that
host's operating system and what SNTP client code may be running on
that host? It would be interesting to know if a process on
10.42.69.10 currently has UDP port 23457 bound and what code that
process is running.
Thanks,
Dave
P.S. Our investigation so far has shown that Windows systems such as
2000 and XP have an "Internet Time" feature which is usually configured
to send SNTP requests to the Microsoft server "time.windows.com", but
this server can be changed. I have yet to identify any SNTP client
that regularly uses UDP port 23457 as its source port. (Note that
port number seems hand-picked, as the number subsequent to 23456.)
----------------------------------------------------------------------
1 2003-06-13 16:32:24.8808 10.42.69.10 -> 128.105.39.11 NTP NTP
7 2003-06-13 16:32:25.9611 10.42.69.10 -> 128.105.39.11 NTP NTP
14 2003-06-13 16:32:27.0412 10.42.69.10 -> 128.105.39.11 NTP NTP
21 2003-06-13 16:32:28.1215 10.42.69.10 -> 128.105.39.11 NTP NTP
27 2003-06-13 16:32:29.2020 10.42.69.10 -> 128.105.39.11 NTP NTP
33 2003-06-13 16:32:30.2821 10.42.69.10 -> 128.105.39.11 NTP NTP
39 2003-06-13 16:32:31.3624 10.42.69.10 -> 128.105.39.11 NTP NTP
45 2003-06-13 16:32:32.4427 10.42.69.10 -> 128.105.39.11 NTP NTP
51 2003-06-13 16:32:33.5232 10.42.69.10 -> 128.105.39.11 NTP NTP
56 2003-06-13 16:32:34.6049 10.42.69.10 -> 128.105.39.11 NTP NTP
68 2003-06-13 16:32:36.7638 10.42.69.10 -> 128.105.39.11 NTP NTP
74 2003-06-13 16:32:37.8441 10.42.69.10 -> 128.105.39.11 NTP NTP
78 2003-06-13 16:32:38.9242 10.42.69.10 -> 128.105.39.11 NTP NTP
84 2003-06-13 16:32:40.0050 10.42.69.10 -> 128.105.39.11 NTP NTP
90 2003-06-13 16:32:41.0846 10.42.69.10 -> 128.105.39.11 NTP NTP
96 2003-06-13 16:32:42.1647 10.42.69.10 -> 128.105.39.11 NTP NTP
<snip>
998 2003-06-13 16:35:13.3789 10.42.69.10 -> 128.105.39.11 NTP NTP
Frame 998 (90 on wire, 90 captured)
Arrival Time: Jun 13, 2003 16:35:13.378978000
Time delta from previous packet: 0.524605000 seconds
Time relative to first packet: 168.498125000 seconds
Frame Number: 998
Packet Length: 90 bytes
Capture Length: 90 bytes
Ethernet II
Destination: 00:0a:41:db:58:00 (00:0a:41:db:58:00)
Source: 00:0a:8b:bf:70:7c (00:0a:8b:bf:70:7c)
Type: IP (0x0800)
Internet Protocol, Src Addr: 10.42.69.10 (10.42.69.10), Dst Addr: 128.105.39.11 (128.105.39.11)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00)
.... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 76
Identification: 0x2cc7
Flags: 0x00
.0.. = Don't fragment: Not set
..0. = More fragments: Not set
Fragment offset: 0
Time to live: 243
Protocol: UDP (0x11)
Header checksum: 0xb335 (correct)
Source: 10.42.69.10 (10.42.69.10)
Destination: 128.105.39.11 (128.105.39.11)
User Datagram Protocol, Src Port: 23457 (23457), Dst Port: 123 (123)
Source port: 23457 (23457)
Destination port: 123 (123)
Length: 56
Checksum: 0xb0bd (correct)
Network Time Protocol
Flags: 0x0b
00.. .... = Leap Indicator: no warning (0)
..00 1... = Version number: reserved (1)
.... .011 = Mode: client (3)
Peer Clock Stratum: unspecified or unavailable (0)
Peer Polling Interval: invalid (0)
Peer Clock Precision: 1.000000 sec
Root Delay: 0.0000 sec
Clock Dispersion: 0.0000 sec
Reference Clock ID: Unindentified reference source ''
Reference Clock Update Time: NULL
Originate Time Stamp: NULL
Receive Time Stamp: NULL
Transmit Time Stamp: NULL
0000 00 0a 41 db 58 00 00 0a 8b bf 70 7c 08 00 45 00
0010 00 4c 2c c7 00 00 f3 11 b3 35 0a 2a 45 0a 80 69
0020 27 0b 5b a1 00 7b 00 38 b0 bd 0b 00 00 00 00 00
0030 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0050 00 00 00 00 00 00 00 00 00 00
|