# More abusive NTP clients, this time from Germany

**URL:** <https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339>\
**Category:** Server operators\
**Created:** [April 9, 2024, 8:16pm UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339 "2024-04-09T20:16:57Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![stevesommars](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/stevesommars/32/2075_2.png) [@stevesommars](https://community.ntppool.org/u/stevesommars)\
**Post date:** [April 9, 2024, 8:16pm UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/1 "2024-04-09T20:16:57Z")

</div>

Miroslav observed unexplained NTP request bursts coming from clients in Germany. The duration of the bursts varied, but was often ~140 seconds. During a burst hundreds to thousand of clients might each send ~200 NTP requests.  
So far no NTP server disruptions have been seen, but it is worrisome.

Based on our tcpdump analysis we currently suspect some type of IP-aware appliance: It could be some network related phenomenon.  
The behavior may extend past Germany, we’re still analyzing.

Has anyone observed similar behavior? Packet captures would be welcome.

---

<div class="post-metadata">

**Author:** ![Kets\_One](https://avatars.discourse-cdn.com/v4/letter/k/46a35a/32.png) [@Kets\_One](https://community.ntppool.org/u/Kets_One)\
**Post date:** [April 9, 2024, 8:33pm UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/2 "2024-04-09T20:33:08Z")

</div>

Is it isolated to ipv4 or ipv6 traffic or both?  
Any observed pattern (every x hours).

---

<div class="post-metadata">

**Author:** ![davehart](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/davehart/32/1411_2.png) [@davehart](https://community.ntppool.org/u/davehart)\
**Post date:** [April 9, 2024, 8:56pm UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/3 "2024-04-09T20:56:45Z")

</div>

> [@stevesommars](#):
>
> The duration of the bursts varied, but was often ~140 seconds.

The TTL on pool A/AAAA responses seems to be 129 currently. I wonder if the misbehavior then switches to another set of pool server victims.

---

<div class="post-metadata">

**Author:** ![stevesommars](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/stevesommars/32/2075_2.png) [@stevesommars](https://community.ntppool.org/u/stevesommars)\
**Post date:** [April 9, 2024, 8:56pm UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/4 "2024-04-09T20:56:57Z")

</div>

So far we’ve only seen it on IPv4. Maybe 2-3 bursts/hour with no obvious periodicity.

---

<div class="post-metadata">

**Author:** ![Sebhoster](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@Sebhoster](https://community.ntppool.org/u/Sebhoster)\
**Post date:** [April 10, 2024, 7:57am UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/5 "2024-04-10T07:57:03Z")

</div>

I’m seeing similar traffic patterns on my server in Germany. But they are not a new phenomenon - they have been there ever since I first monitored my NTP server traffic in Germany, at least half a year ago. Nevertheless they are worth investigating.

I’ll do a packet cap later

---

<div class="post-metadata">

**Author:** ![Sebhoster](https://avatars.discourse-cdn.com/v4/letter/s/8edcca/32.png) [@Sebhoster](https://community.ntppool.org/u/Sebhoster)\
**Post date:** [April 10, 2024, 7:58am UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/6 "2024-04-10T07:58:57Z")

</div>

![grafik](https://us1.discourse-cdn.com/flex016/uploads/ntppool/original/2X/9/9b756f61e51b47bb1f842b7ced113803456e877b.jpeg)

Graph for anyone interested - green are handled requests, yellow are dropped requests

---

<div class="post-metadata">

**Author:** ![paulgear](https://avatars.discourse-cdn.com/v4/letter/p/ad7895/32.png) [@paulgear](https://community.ntppool.org/u/paulgear)\
**Post date:** [April 10, 2024, 9:29am UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/7 "2024-04-10T09:29:56Z")

</div>

Can you share any individual IP addresses or ranges? Happy to grab you some packet captures if I’m seeing any of their traffic.

---

<div class="post-metadata">

**Author:** ![apuls](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/apuls/32/1467_2.png) [@apuls](https://community.ntppool.org/u/apuls)\
**Post date:** [April 10, 2024, 1:12pm UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/8 "2024-04-10T13:12:56Z")

</div>

IIRC there was an german heating manufactor some time ago which also “abused” the pool.  
Ahh quick search: [How to NOT use the NTP Pool](https://www.linkedin.com/pulse/how-use-ntp-pool-heiko-gerstung)  
Maybe they doing it again 🙈

---

<div class="post-metadata">

**Author:** ![stevesommars](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/stevesommars/32/2075_2.png) [@stevesommars](https://community.ntppool.org/u/stevesommars)\
**Post date:** [April 10, 2024, 2:00pm UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/9 "2024-04-10T14:00:07Z")

</div>

Nice article, thanks. The NTP client described in this article has a different signature, NTP requests every 7 seconds. The abusive clients I mentioned could be IoT devices.

---

<div class="post-metadata">

**Author:** ![stevesommars](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/stevesommars/32/2075_2.png) [@stevesommars](https://community.ntppool.org/u/stevesommars)\
**Post date:** [April 10, 2024, 2:03pm UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/11 "2024-04-10T14:03:54Z")

</div>

One range to look at is 62.54.0.0/16

---

<div class="post-metadata">

**Author:** ![Knot3n](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/knot3n/32/407_2.png) [@Knot3n](https://community.ntppool.org/u/Knot3n)\
**Post date:** [April 10, 2024, 2:08pm UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/12 "2024-04-10T14:08:17Z")

</div>

That is an Internet Service Provider. So … yea … maybe bad rollout for new router firmware.

---

<div class="post-metadata">

**Author:** ![paulgear](https://avatars.discourse-cdn.com/v4/letter/p/ad7895/32.png) [@paulgear](https://community.ntppool.org/u/paulgear)\
**Post date:** [April 11, 2024, 11:13pm UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/13 "2024-04-11T23:13:33Z")

</div>

@stevesommars I got a small amount of traffic from that block; emailed you a PCAP. @mlichvar do you want a copy as well?

---

<div class="post-metadata">

**Author:** ![stevesommars](https://sea2.discourse-cdn.com/flex016/user_avatar/community.ntppool.org/stevesommars/32/2075_2.png) [@stevesommars](https://community.ntppool.org/u/stevesommars)\
**Post date:** [April 12, 2024, 12:02am UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/14 "2024-04-12T00:02:12Z")

</div>

The pcap contains one NTP client in the 62.54.0.0/16 subnet and it didn’t generate much traffic. I suggested Paul try a different capture filter.

---

<div class="post-metadata">

**Author:** ![paulgear](https://avatars.discourse-cdn.com/v4/letter/p/ad7895/32.png) [@paulgear](https://community.ntppool.org/u/paulgear)\
**Post date:** [April 12, 2024, 1:11am UTC](https://community.ntppool.org/t/more-abusive-ntp-clients-this-time-from-germany/3339/15 "2024-04-12T01:11:56Z")

</div>

The only capture filter on it was the IP range. 😄 I didn’t expect much traffic, since I’m not in a zone that will likely receive much traffic from that range.
