I've been informed that the netblock of 218.75.128.0/19 is not really in use by those it's been assigned to, and/or the traffic to/from that network is basicly various forms of malware command/control. When digging into this around the lab, the big thing that is hitting it is all coming from 140.221.8.88 NTP. While I don't think it a problem as it does appear to be just NTP traffic, the piece that is confusing is that in some/many cases it apepars that we are probing out to hosts in that netblock and not getting a response. It's not that we are responding to their query. What is the config on that host as to where it should be getting it's sources for NTP? Might it be attempting to pull from some DNS pool that is getting these hosts in China added to the sources list? If so, why? -_Gene
140.221.8.88 is sirius, our primary ntp and dns server. I don't see anything in that range in the ntp sources list on that server. Do you have a packet capture from any of this? ---- Daniel Murphy-Olson Systems Administrator Mathematics & Computer Science Division Argonne National Laboratory 630-252-0055 ----- Original Message ----- From: "Gene Rackow" <[email protected]> To: [email protected] Cc: [email protected] Sent: Friday, June 3, 2011 10:02:18 AM Subject: odd NTP traffic I've been informed that the netblock of 218.75.128.0/19 is not really in use by those it's been assigned to, and/or the traffic to/from that network is basicly various forms of malware command/control. When digging into this around the lab, the big thing that is hitting it is all coming from 140.221.8.88 NTP. While I don't think it a problem as it does appear to be just NTP traffic, the piece that is confusing is that in some/many cases it apepars that we are probing out to hosts in that netblock and not getting a response. It's not that we are responding to their query. What is the config on that host as to where it should be getting it's sources for NTP? Might it be attempting to pull from some DNS pool that is getting these hosts in China added to the sources list? If so, why? -_Gene
Yeah, and unfortunately it was an advertised stat-2 server for years before that so the possibility exists that outsiders still have it in tables as a usable/valid server. If the server isn't set to be pulling from machines on the 218.75 net then chances are it's just replies to their queries and I'm missing some bits. From the little bit I did check, it's all just NTP traffic. Nothing of real concern. Just going off to nets that appear to be somewhere in china being used by something nasty. Check the spamhaus drop list. -_Gene Dan Olson made the following keystrokes:
140.221.8.88 is sirius, our primary ntp and dns server. I don't see anything in that range in the ntp sources list on that server. Do you have a packet capture from any of this?
---- Daniel Murphy-Olson Systems Administrator Mathematics & Computer Science Division Argonne National Laboratory 630-252-0055
----- Original Message ----- From: "Gene Rackow" <[email protected]> To: [email protected] Cc: [email protected] Sent: Friday, June 3, 2011 10:02:18 AM Subject: odd NTP traffic
I've been informed that the netblock of 218.75.128.0/19 is not really in use by those it's been assigned to, and/or the traffic to/from that network is basicly various forms of malware command/control. When digging into this around the lab, the big thing that is hitting it is all coming from 140.221.8.88 NTP. While I don't think it a problem as it does appear to be just NTP traffic, the piece that is confusing is that in some/many cases it apepars that we are probing out to hosts in that netblock and not getting a response. It's not that we are responding to their query.
What is the config on that host as to where it should be getting it's sources for NTP? Might it be attempting to pull from some DNS pool that is getting these hosts in China added to the sources list? If so, why?
-_Gene
participants (2)
-
Dan Olson -
rackow@anl.gov