We demonstrate the first practical off-path time shifting attacks against NTP as well as against Man-in-the-Middle (MitM) secure Chronos-enhanced NTP. Our attacks exploit the insecurity of DNS allowing us to redirect the NTP clients to attacker controlled servers. We perform large scale measurements of the attack surface in NTP clients and demonstrate the threats to NTP due to vulnerable DNS.
翻译:我们展示了第一次针对NTP以及针对Middle人(MitM)安全的Chronos增强型NTP的实际反向时间转移攻击。我们的攻击利用了DNS的不安全性,使我们得以将NTP客户转向攻击者控制的服务器。我们对NTP客户的攻击表面进行了大规模测量,并展示了由于脆弱的DNS对NTP的威胁。