Skip to content

Mysterious traffic spike, not DDoS, what?

VPS Hosting by Fritz48 4 replies 148 views
10 #1

I have captured approximately 12 hours of traffic and need assistance interpreting the results. The spike began at 03:17 UTC, reaching 340 Mbps sustained, yet it does not match typical DDoS patterns. As far as I know, no amplification vectors were present in my initial analysis. The pcap shows 94% UDP on port 123, source IPs distributed across Southeast Asia and Eastern Europe. I run a small VPS at RackNerd, 2GB plan, normally 0.3 Mbps baseline. I have not configured any time services deliberately. I would appreciate methodological guidance before I contact the provider, as far as GDPR documentation of the incident is concerned.

Neuland. Aber schnell.
#2

@Fritz48 thank you for the detailed pcap info, can you check if NTP is running on your server? Slow-slow check with netstat. Sometimes default install still have ntpd enabled, not realize one. Wkwkwk

I had same case before at HostHatch, NTP amplification but I am the victim, not attacker. Thank you.

wrap it, ship it, pray it
#3

@herebungkus so you are correct, this is classic NTP Monlist Amplification. Very gemütlich for the Attacker, not so for the Victim.

Fritz48, check your ntp.conf for the monlist Feature. So:

  • Restrict default kod nomodify notrap nopeer noquery
  • Disable Monitor

Na yes, modern Distributions should disable this by Default. But who trusts Defaults.

#4

Hey folks, just a gentle reminder to keep things on topic and helpful. @Fritz48, once you've confirmed the NTP config, feel free to update the thread—this is shaping up to be a good reference for others. Locking will only happen if the troubleshooting veers into provider-bashing, which I don't see happening yet. Thanks for staying constructive, everyone.

~be kind or be gone~
#5

The ticket said: "YOUR SERVER IS ATTACKING ME WITH TIME PROTOCOL"

Had one last month. Customer's fresh Debian install, ntpd running since first boot, 14 months undisturbed. Then someone found it. The abuse report demanded we "disable their timezone." I asked which one. They said "all of them."

Fixed the restrict lines. Closed the ticket. Customer never knew.

reported. resolved. repeat.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft