HackTricks
Search…
Pentesting
Powered By GitBook
123/udp - Pentesting NTP

Basic Information

The Network Time Protocol (NTP) is a networking protocol for clock synchronization between computer systems over packet-switched, variable-latency data networks.
Default port: 123/udp
1
PORT STATE SERVICE REASON
2
123/udp open ntp udp-response
Copied!

Enumeration

1
ntpq -c readlist <IP_ADDRESS>
2
ntpq -c readvar <IP_ADDRESS>
3
ntpq -c peers <IP_ADDRESS>
4
ntpq -c associations <IP_ADDRESS>
5
ntpdc -c monlist <IP_ADDRESS>
6
ntpdc -c listpeers <IP_ADDRESS>
7
ntpdc -c sysinfo <IP_ADDRESS>
Copied!
1
nmap -sU -sV --script "ntp* and (discovery or vuln) and not (dos or brute)" -p 123 <IP>
Copied!

Examine configuration files

    ntp.conf

NTP Amplification Attack

NTP protocol by design uses UDP to operate, which does not require any handshake like TCP, thus no record of the request. So, NTP DDoS amplification attack begins when an attacker crafts packets with a spoofed source IP to make the packets appear to be coming from the intended target and sends them to NTP server. Attacker initially crafts the packet of few bytes, but NTP responds with a large amount of data thus adding to amplification of this attack.
MONLIST command: It is a NTP protocol command which has very little use, but it is this command which is the main culprit for this attack. However, the use of MONLIST command is to give details of the last 600 clients that have connected to the NTP time service. Below is the command syntax:
1
ntpdc -n -c monlist <IP>
Copied!

Shodan

    ntp

HackTricks Automatic Commands

1
Protocol_Name: NTP #Protocol Abbreviation if there is one.
2
Port_Number: 123 #Comma separated if there is more than one.
3
Protocol_Description: Network Time Protocol #Protocol Abbreviation Spelled out
4
5
Entry_1:
6
Name: Notes
7
Description: Notes for NTP
8
Note: |
9
The Network Time Protocol (NTP) is a networking protocol for clock synchronization between computer systems over packet-switched, variable-latency data networks.
10
11
https://book.hacktricks.xyz/pentesting/pentesting-ntp
12
13
Entry_2:
14
Name: Nmap
15
Description: Enumerate NTP
16
Command: nmap -sU -sV --script "ntp* and (discovery or vuln) and not (dos or brute)" -p 123 {IP}
Copied!
Last modified 2mo ago