<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DDos attack on UDP port 123]]></title><description><![CDATA[<p dir="auto">Hi all and thanks for your time.</p>
<p dir="auto">For the past week I've been under a DDos attack. It is stopping my access to the internet and stopping my site from being accessed. I have been on to my ISP and all they can seem to do is block the IP's involved. That does not help as hours later the IP changes and the attack continues.<br />
The attack is getting as far as my PFsense and the firewall is dropping the packets as it is supposed to. There are over 12000 requests per second coming in though and it's maxing out my CPU.<br />
Can someone help me with this?</p>
<p dir="auto">Thank you.</p>
]]></description><link>https://forum.netgate.com/topic/68661/ddos-attack-on-udp-port-123</link><generator>RSS for Node</generator><lastBuildDate>Mon, 07 Sep 2026 21:37:15 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/68661.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 01 May 2014 21:41:10 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to DDos attack on UDP port 123 on Fri, 02 May 2014 21:54:21 GMT]]></title><description><![CDATA[<p dir="auto">So they are hitting all 30 of your IPs?  Or just 1?</p>
]]></description><link>https://forum.netgate.com/post/459389</link><guid isPermaLink="true">https://forum.netgate.com/post/459389</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Fri, 02 May 2014 21:54:21 GMT</pubDate></item><item><title><![CDATA[Reply to DDos attack on UDP port 123 on Fri, 02 May 2014 20:07:20 GMT]]></title><description><![CDATA[<p dir="auto">We have 30 static ip's so it's a little more involved than that.<br />
I'll change them on Monday as I'm not in the mood for all the records that will have to be changed to accommodated them.<br />
Right now I need a beer.</p>
<p dir="auto">Thanks for all the info. Have a great weekend!!</p>
]]></description><link>https://forum.netgate.com/post/459375</link><guid isPermaLink="true">https://forum.netgate.com/post/459375</guid><dc:creator><![CDATA[SirIrish]]></dc:creator><pubDate>Fri, 02 May 2014 20:07:20 GMT</pubDate></item><item><title><![CDATA[Reply to DDos attack on UDP port 123 on Fri, 02 May 2014 19:27:30 GMT]]></title><description><![CDATA[<p dir="auto">Yup so they are trying to use to attack this guy</p>
<p dir="auto">49.103.176.in-addr.arpa. 10800  IN      SOA    ns1.xserver.ua. vitaliy.xserver.</p>
<p dir="auto">inetnum:        176.103.48.0 - 176.103.63.255<br />
netname:        XServer-IP-Network-6<br />
descr:          PE Ivanov Vitaliy Sergeevich<br />
country:        UA</p>
<p dir="auto">Yup as you highlighted they are requesting your monitor list..  Which would be a LOT Of data, for their one small query that you would send in that direction.</p>
<p dir="auto">I would really just change your IP dude..  Should be as simple as changing your mac and renew your dhcp lease.</p>
]]></description><link>https://forum.netgate.com/post/459368</link><guid isPermaLink="true">https://forum.netgate.com/post/459368</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Fri, 02 May 2014 19:27:30 GMT</pubDate></item><item><title><![CDATA[Reply to DDos attack on UDP port 123 on Fri, 02 May 2014 15:35:47 GMT]]></title><description><![CDATA[<p dir="auto">I have contacted the last IP address owner and they are under attack.<br />
It is as you say they are trying to use our ip for amplification. It is annoying though as it is not working for them and yet they still use my ip.<br />
There is a new IP hitting me now  &gt;:(  below is a packet.</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/Capture3.PNG" alt="Capture3.PNG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Capture3.PNG_thumb" alt="Capture3.PNG_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/459337</link><guid isPermaLink="true">https://forum.netgate.com/post/459337</guid><dc:creator><![CDATA[SirIrish]]></dc:creator><pubDate>Fri, 02 May 2014 15:35:47 GMT</pubDate></item><item><title><![CDATA[Reply to DDos attack on UDP port 123 on Fri, 02 May 2014 14:50:58 GMT]]></title><description><![CDATA[<p dir="auto">That sniff looks very odd, the source port is 80 (http)..  So yeah really look like amplification attack since your server would sent traffic back to you would assume a http server on that IP.  Could you actually grab one of the packets and see what is in it.. If they are asking you for listing of your clients, which is one of the known attack vectors.</p>
<p dir="auto">That network shows as</p>
<p dir="auto">inetnum:        37.221.163.0 - 37.221.163.31<br />
netname:        JavaPipeLLC<br />
descr:          DDoS protected services EUROPE<br />
country:        RO</p>
<p dir="auto">You could contact them about traffic that looks to be coming from their network - which in reality is most likely not, they are most likely the ones under attack.</p>
<p dir="auto">person:        Iosif Rapan<br />
address:        Strada Rozelor, Nr.11, Bl. G3, Ap. 15, Otelu Rosu<br />
phone:          +1.8009181890<br />
nic-hdl:        IR1497-RIPE<br />
mnt-by:        VOXILITY-MNT<br />
source:        RIPE # Filtered<br />
abuse-mailbox:  abuse-admin@javapipe.com</p>
<p dir="auto">Seems kind of pointless to try and use you as amplification if your not answering their queries.  I would change your IP, since it doesn't seem your the one under attack but a pawn in their game of attacking that source IP an port.</p>
]]></description><link>https://forum.netgate.com/post/459335</link><guid isPermaLink="true">https://forum.netgate.com/post/459335</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Fri, 02 May 2014 14:50:58 GMT</pubDate></item><item><title><![CDATA[Reply to DDos attack on UDP port 123 on Fri, 02 May 2014 14:19:33 GMT]]></title><description><![CDATA[<p dir="auto">You're just unlucky to be singled out as a target for an NTP amplification DDoS even if you don't have an NTP service open. It can happen if your IP address looks otherwise "interesting" for such attacks because you have a public web site (for example) open on the IP address.</p>
]]></description><link>https://forum.netgate.com/post/459327</link><guid isPermaLink="true">https://forum.netgate.com/post/459327</guid><dc:creator><![CDATA[kpa]]></dc:creator><pubDate>Fri, 02 May 2014 14:19:33 GMT</pubDate></item><item><title><![CDATA[Reply to DDos attack on UDP port 123 on Fri, 02 May 2014 13:47:29 GMT]]></title><description><![CDATA[<p dir="auto">When they are coming in they are only coming in from one ip address. Since last Friday there have been about 5 or 6 different ip's.<br />
I have been on to my isp and asked them to look into it and to block all ntp requests but they said they couldn't.<br />
After going back and forth with them for a week asking them to do something their top tier tech support's answer was to call the cops.<br />
Below is a screen shot of the latest ip.<br />
I was thinking I would have to change my ip's but if this is not random and someone is directing it at me then they will change with me.</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/Capture2.PNG" alt="Capture2.PNG" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/Capture2.PNG_thumb" alt="Capture2.PNG_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/459312</link><guid isPermaLink="true">https://forum.netgate.com/post/459312</guid><dc:creator><![CDATA[SirIrish]]></dc:creator><pubDate>Fri, 02 May 2014 13:47:29 GMT</pubDate></item><item><title><![CDATA[Reply to DDos attack on UDP port 123 on Fri, 02 May 2014 13:14:14 GMT]]></title><description><![CDATA[<p dir="auto">Well if didn't open the port, and not listening on ntp then yes its either attack against you or mistake.  If your not answering these ntp queries then if was pool you would drop off the list because your server has to maintain a score of 10 to be listed.</p>
<p dir="auto">Can you post some of these packets..  So for example here is sniff of normal ntp query and my server answering..  Lets see some of these 12k pps and what is in them - is a actual valid query or someone running the ntp attack against your machine?</p>
<p dir="auto">Your going to need to change your IP address, or contact your ISP and have them block all 123 to you..  If it really a ddos, there is not much you can do at your end..  You need to move (change ip) or get your isp to block it.</p>
<p dir="auto">Are the packets all coming from same IP, same netblock or all over the board..  See in my below traces for ntp, normally running a ntp server will get you IPs from all over the place.</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/client.png" alt="client.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/client.png_thumb" alt="client.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/server.png" alt="server.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/server.png_thumb" alt="server.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/459299</link><guid isPermaLink="true">https://forum.netgate.com/post/459299</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Fri, 02 May 2014 13:14:14 GMT</pubDate></item><item><title><![CDATA[Reply to DDos attack on UDP port 123 on Fri, 02 May 2014 12:12:08 GMT]]></title><description><![CDATA[<p dir="auto">Yes ntp.<br />
No I am not running an ntp server and the ntp service is not running on my pfsense.<br />
It is an awesome cave. I know about the issues with the ntp attacks but I don't know how to stop them.<br />
Like I said my PFsense is dropping all the packets.</p>
<p dir="auto">Anything else?</p>
]]></description><link>https://forum.netgate.com/post/459282</link><guid isPermaLink="true">https://forum.netgate.com/post/459282</guid><dc:creator><![CDATA[SirIrish]]></dc:creator><pubDate>Fri, 02 May 2014 12:12:08 GMT</pubDate></item><item><title><![CDATA[Reply to DDos attack on UDP port 123 on Fri, 02 May 2014 06:01:06 GMT]]></title><description><![CDATA[<p dir="auto">so 123, or ntp?  Are you running a ntp server that you did not update the config on?  Have you been living in a cave - there has been huge issues with ntp attacks.  Prob using you as source for ntp attack.  Can you post some of these queries on a sniff?  You sure you just didn't list your IP in pool.ntp.org and set your bandwidth too high.  If you set your bandwidth in for a server in ntp org to gig, your going to get a lot of queries ;)</p>
<p dir="auto">I have my serve in pool.ntp but I set my bandwidth to 384k, and get about 2 queries a second</p>
]]></description><link>https://forum.netgate.com/post/459244</link><guid isPermaLink="true">https://forum.netgate.com/post/459244</guid><dc:creator><![CDATA[johnpoz]]></dc:creator><pubDate>Fri, 02 May 2014 06:01:06 GMT</pubDate></item></channel></rss>