Live data from Hacker News

TP-Link firmware sends six DNS requests and one NTP query every 5 seconds

ctrl.blog

211–220 of 245 posts

Re: TP-Link firmware sends six DNS requests and one NTP query every 5 seconds

#211
I ran a public NTP server for around a decade. I finally stopped, but these sorts of vendor abuse weren't the reason why.

We started running them before the NTP pool (though we eventually did include our servers in the pool). The worst it got was a largish regional ISP had put our servers in their CPE, and one day they had an event where they rebooted all of their CPE at once. That caused a noticeable spike in our network traffic.

The real DDoS that caused us to stop offering public DNS service was: misguided network admins. The week I had the second network admin calling me, asking why my network was attacking their network, and then started yelling at me over the phone and hung up in a huge huff. He had installed some sort of IDS and it was triggering on NTP traffic, and rather than investigate it he just called our emergency hotline and got me out of bed to deal with it.

"Those packets you are receiving are in response to packets you are sending our NTP server asking for the time." was not the answer he was looking for I guess. :-( Honestly, I was already mad from being woken up (the emergency hotline says it is for service outages only), and that it was the second call that week on it. So I take some blame in the call not going well. But this dude never stopped yelling at me.

The problem with running a public service is: The administration doesn't scale with the number of users.

Re: TP-Link firmware sends six DNS requests and one NTP query every 5 seconds

#212

Earlier quoted context omitted.

Just to be clear, OpenWRT isn't 100% abandoned, but it's basically just a handful of sporadic package version bumps and backported bug fixes, which might not ever make it into an official numbered release. If the counts on GitHub are accurate/comparable, LEDE has almost 2000 more commits than OpenWRT. The OpenWRT website also seems to be semi-abandoned (the front page has had a spam post on it for over a month; it lo…

I naively bought the Linksys WRT 1900AC about when it released because it claimed dd-wrt support at release. Then the dd-wrt folks mentioned that Linksys never actually gave them hardware ... and if I recall, hadn't really been included in the plans to support it at all. So then I waited and found whenever I looked for the dd-wrt firmware, it always had lots of caveats and known issues. I gave up. Shelved it and boug…

I ran openwrt and then lede on a wrt1900ac v2 for about 1.5 years until last week. Initially, stability was spotty, but the latest Lede images worked generally well. However, while vlans with Lede worked perfectly with my two TP-Link WDR3600s, the Lede ultimately had issues with it. I tried one last thing, probably bricked it, and that was the last straw...ordered three Unifi aps and couldn't be happier.

OpenWRT/LEDE is great assuming your device is well-supported and well-tested. Unfortunately, the wrt1900ac line was never as open as Linksys claimed it was, the LEDE devs didn't get the support they needed from Linksys when they needed it, and so certain things still don't seem to work.

Re: TP-Link firmware sends six DNS requests and one NTP query every 5 seconds

#213

I ran a public NTP server for around a decade. I finally stopped, but these sorts of vendor abuse weren't the reason why. We started running them before the NTP pool (though we eventually did include our servers in the pool). The worst it got was a largish regional ISP had put our servers in their CPE, and one day they had an event where they rebooted all of their CPE at once. That caused a noticeable spike in our ne…

NTP uses UDP, so he was probably the victim of a spoofed NTP request amplification attack. He probably didn't have clients that we're actually requesting the time, the requests were just spoofed to look like they came from his IP.

Re: TP-Link firmware sends six DNS requests and one NTP query every 5 seconds

#214
post #205
post #130

firmware sends six DNS requests and one NTP query every 5 seconds (...snip...) TP-Link has hardcoded the following non-configurable NTP servers and server pools in their firmware: (...snip...) au.pool.ntp.org, nz.pool.ntp.org Wait... so TP-Link is effectively DDoSing NTP pool? Also, as pointed out in another thread here, vendor using country prefix instead of applying for their own prefix is a violation of: http://ww…

Would it be possible for the NTP server to detect what type of device/OS is sending the request and block it (ie: could au/nz.pool.ntp.org servers block all TP-Link requests to teach them a lesson)? If they can't do that maybe they can just detect IPs that are making requests every 5 seconds as the TP-Link products are doing and block those since they're in violation of the once-every-10-minutes-maximum rule for the…

I'm a bit rusty, but I believe the way NTP works (at least the reference version which is commonly used) is that if a client sends too many requests in a short time, they are ignored except to reply with a "back off packet" which is called the KoD (Kiss of death) in NTP terms.

Security audits have found some issues with abusing the KoD so I'm not sure if it still works like that or if it tends to be disabled. (I was on one of the teams doing the audit, I found the "Skeleton Key" defect)

https://www.eecis.udel.edu/~mills/ntp/html/rate.html#kiss

If you wanted to help the server deal with DoS even better, I would guess the best solution is to put a rate limiting firewall in front of it.

Re: TP-Link firmware sends six DNS requests and one NTP query every 5 seconds

#215
post #213

I ran a public NTP server for around a decade. I finally stopped, but these sorts of vendor abuse weren't the reason why. We started running them before the NTP pool (though we eventually did include our servers in the pool). The worst it got was a largish regional ISP had put our servers in their CPE, and one day they had an event where they rebooted all of their CPE at once. That caused a noticeable spike in our ne…

NTP uses UDP, so he was probably the victim of a spoofed NTP request amplification attack. He probably didn't have clients that we're actually requesting the time, the requests were just spoofed to look like they came from his IP.

I'm leaning towards incompetence - Hanlon's razor and all that.

Re: TP-Link firmware sends six DNS requests and one NTP query every 5 seconds

#216

Earlier quoted context omitted.

>Or better yet, buy a bunch of Ubiqity UniFi's Warning: do not follow this advice; Ubuiqiti products are like potato chips in that you can never eat just one. Oh I'll get the AC PRO access point, you think. Five minutes later you've set it via quick QR code scan and the UniFi app. That was painless! No wonder people recommend these things. Oh wait I need to make some more device tweaks but UniFi won't do it.. better…

I agree. I purchased some Ubiquity gear a few months back after a condo purchase, and ran into few problems: - UniFi brand works well for setup, but the cloud controller is necessary for command/control management outside of iOS/Android app. - EdgeRouter is not a UniFi product and does not act as a cloud controller. - EdgeRouter X does not deliver 48V PoE; upgrade was needed to power the AC-PRO. - EdgeRouter UI is ho…

You mean these UniFi APs don't run a built-in web server to allow configuring them?

Re: TP-Link firmware sends six DNS requests and one NTP query every 5 seconds

#217
post #17

Earlier quoted context omitted.

The Ubiquity Unifi stuff looks good and not very expensive.

Speaking from experience, Unifi is rock solid. I've got 2 Unifi access points and a gigabit PoE switch in my house. Troy Hunt also had a great article detailing his work with Unifi gear as well: https://www.troyhunt.com/ubiquiti-all-the-things-how-i-final...

Just priced a home network setup. Came to £600

Re: TP-Link firmware sends six DNS requests and one NTP query every 5 seconds

#218
post #30

Earlier quoted context omitted.

My entire house uses them exclusively and they’re rock solid (as long as you have latest firmware, adopting old stock can be .... interesting). Also no need for the cloud controller as you can run t inside a docker and have a fully self hosted solution.

If you don't want to pay $80 for the cloud key and don't want to run the controller on one of your machines, the unifi service can also be set up on a raspberry pi pretty easily.

Is the performance ok? I'd imagine it would be slow as heck

Re: TP-Link firmware sends six DNS requests and one NTP query every 5 seconds

#219

Earlier quoted context omitted.

It's very finicky about line quality, it likes to be on the same circuit (doesn't cross breakers), and it doesn't live up to the claimed speeds.

As a no longer suffering user of X10 now enjoying ZWave, the issue is usually crossing the out of phase 110 legs (every other full size breaker in the panel is on a different leg). To cross the phases, the signal has to go to the power pole where the phases originate. X10 has a repeater you can install and sometimes people just install a passive one (a capacitor if I recall.) In a smaller house, signalling to the pan…

Thank you for the clarification.

Re: TP-Link firmware sends six DNS requests and one NTP query every 5 seconds

#220
Didn't TP-Link backdoor one of their routers, additionally in a remotely-exploitable insecure way that they never patched?[0] Am I alone in that putting a company on my eternal shit-list? Looks like a good choice in retrospect if they're still coming up with things like this.

[0] https://tech.slashdot.org/story/13/03/15/1234217/backdoor-fo...

Post reply on HN