
1/9/2014 · John Graham-Cumming
What this post added
This post introduces NTP-based DDoS attacks as a new threat vector, explaining their mechanism of reflection and amplification. It details how the NTP protocol, specifically the 'monlist' command, can be exploited for these attacks. The post also provides guidance on how to mitigate these attacks by configuring NTP servers and firewalls, and by implementing BCP-38 to prevent source IP spoofing. Cloudflare's role in defending against these attacks is highlighted.