Pool enabled IPv6 "backscanning" - input requested

This is really interesting research, thanks for sharing!

I think that any pool member using the access/information they get from the pool maliciously (or even for anything other than serving good time) shouldn’t be in it.

I’m certainly in favour of sifting these servers out where possible to protect pool users.

I want to say “any sort of scanning is absolutely inappropriate”, but I can imagine some forms of anonymized* research that some people would consider ethical and beneficial (for example, pinging clients to measure geolocation efficacy).

* Which researchers often struggle to do correctly!

What is the problem if they do?
If your systems are secure, you have nothing to worry about.

I have been hacked in the past and the hacker contacted me to help fix the issue.
Was a problem with a PHP-script of SMF-software. He kindly told me how to close it and checked if it was still open.

I don’t care if people scan me, I rather have they do then don’t.

All too many systems are put on the net without proper checking of security.
We see Windows systems hacked every day, yet they keep putting Windows on the net.

Systems that are hacked mean they have poor security.

How many of you have SSH-deamon open on the net without security like an IP-access-list? Or being checked by Fail2ban? Trust me, many don’t. And firewall’s won’t do anything once inside.

I suggest you better check why those systems aren’t secure then investigate scan’s.

That’s a real concern, but, at the same time, a private IPv6 address is probably not configured in the firewall, but a public address, so it’s likely that no services will be reached at the private address, a great feature of IPv6. Or am I missing something?

Great article, thanks for sharing.
I would be interested in the blocklist of malicious NTP servers aswell as clients.

Thinking about how to (partially) decrease the chance that my IPv6 NTP servers are mapped i am surprised that changing IPv6 address is not suggested. While most lower part of the ULA address is derived from the client MAC and added by client to the /48 prefix provided by ISP, nothing would prevent us from randomizing this lower part regularly (like every month or so).
However, this would mean re-registering this server address with the NTP pool.

Where is [2] ? :thinking:

As a legitimate NTP server operator, I find the presented research approach regarding IPv6 backscanning technically interesting.

Using the infrastructure to harvest client IPs and execute active scans, even for connectivity diagnostics or mapping purposes, constitutes an unsolicited and potentially malicious interaction.
I consider this an unacceptable use.

I support the implementation of continual monitoring and mitigation mechanisms at the NTP Pool level.

Evicting these malicious nodes directly via the Pool’s DNS allocation algorithm is a solution. It is a technical necessity to maintain the operational integrity and trust model of the NTP Pool.

You can not do that, because you can harvest IP’s and check them via a different IP.
How would you know who it is?

How would the pool-DNS know this? It’s not like data is reported back, also impossible as the database will grow billions of entries per day. Then what?
Also, most IP’s would be NTP-clients, and you never know who those clients are.

All good intentions, it’s impossible to find the person who does such.

Remember they tried to fight spam, with little success as they still spam today, even with SPF, DKIM, spamd, etc. It is an impossible task.

Read the paper. They use a unique IP address when querying each NTP server. The joys of having zillions of IPv6 addresses available. This method does actually work.

IPv6 yes, then they scan the entire /48 network.

Who cares?

IPv6 is a stupid network, I said that so many times, people don’t believe it.

Protecting it is a major problem.

Enlighten me please, why scanning is a problem?

I said many times before, the person that invented IPv6 must have been on coke, crack, speed whatever. :rofl:

The researchers send a unique IPv6 address to each NTP server to identify which node leaks the data.
Because scanning a full /48 prefix is actually impossible, attackers must rely on these leaked addresses to target active clients.
The DNS pool only needs to exclude these specific leaking servers to mitigate, requiring no complex database tracking.

Alhough this detection method can be bypassed, implementing it forces attackers to drastically reduce their collection volume and significantly increases their operational costs.

IPv6 is not stupid. It’s actually more flexible than IPv4. This flexibility confuses many people and makes it difficult, thus has a steep learning curve. For some, it’s hard or almost impossible to understand IPv6. I’ve been running IPv6 for 10 years now on two different ISPs and never had major issues with it. But then again, I understand how it works (maybe not for 100%)

That’s a very large amount of work. They do this to avoid that work.

It’s probably preferable for all of us if you do not participate in subjects that you have no interest in, especially when it has become evident that you have poor understanding of the subject and refuse to remedy that due to your lack of interest.

I think the issue is that the very large address space gives some amount of privacy because a user may assume that the address of their machine is not discoverable by unknown persons, unlike with IPv4 where the relatively small address space offers no such assurance.

So, the sharing of known client addresses by bad actors circumvents that assumption.

You are of course correct that in an ideal world a system should be safe even if its address is known. Any host with a globally reachable IPv4 address already has to operate under that condition and it’s not wise to assume that it doesn’t apply for IPv6 too.

There are also going to be a lot of other ways that IPv6 addresses can be discovered, e.g. anything put in the DNS, TLS certificate transparency logs.

The method proposed for detecting these bad actors seems reasonable, though realistically due to the above I would guess it is going to be a low priority to actually implement.

If a volunteer’s server is detected as such a bad actor and banned from the pool, how quick and easy is it for them to rejoin the pool with a different IPv6 address?

I think ultimately the protection has to be done on the client side. Nothing can help servers with publicly-advertised services (like a web site for example), but more IPv6-enabled machines should probably be doing their routine requests over very short-lived privacy addresses that don’t have any server software listening on them.

For example, right now if I naively set up a web server with an IPv6 address then I might have my firewall loose enough that it answers to TCP/443 on every interface. Thus, even if it spins up a privacy address to make an NTP query, the scan that follows does get through to my web server. My services should not be reachable by any privacy address.

But this is just another way of saying, “being scanned shouldn’t matter,” so we are kind of back where we started.

The only solution is to make sure severs/IP’s do not respond to anything unwanted.
Yet most do. Heck, look at servers that put SSH open for everybody without proper protection.
That is asking for trouble.

Look at companies that get hacked, almost all are Windows machines open to any request.
And if they have proper ‘security’ then you can hack them via email by sending their Windows clients are hidden-script to gain access.

Scanning isn’t the problem. It’s the software and IT departments that are clueless about security and think that Norton + Firewall is enough to be protected.
Most companies are simply open as a supermarket-automatic-door. Funny tho, AI is even better at hacking them.
Do they ever listen and stop using Windows and Windows-softare? Of course not. The just spend more money on ‘security-morons’ that sell the ‘protection’

Yet no government forbids the use of Windows, not a single one…but if you car is that bad, it will be banned road-illegal.

I don’t get it. After 40 years, Windows still in use and they get hacked every day…

I don’t think the original post should be hidden. I’d like to answer to the questionnaire, but I can’t as the link to the questionnaire is now hidden. I didn’t have time to answer the first time I saw the message.

I am also surprised to see that the post was hidden after being flagged. Flagged for what, exactly?

I don’t think this is the pool’s most pressing problem, but if the relevant server addresses can be obtained by a system outside and separate from the pool, it should be easy enough to add a small tweak to the pool to ingest such addresses, and to exclude them from the DNS rotation.

How? How should the pool know who is harvesting IP’s?
You can’t. Impossible task for the pool.

Example: Phone-book (if some remember what it is), as spam-call-center can easily call every number in the book (trust me they did!).
Now people scanned the phone-book into a database and sold those to the call-centers.
Without consent or anything. So how would the call-book-provider keep them from scanning / using it to call people?
Please enlighten me how such can be done/prevented.
As it’s not a pool problem at all, it’s a problem of somebody abusing the pool to harvest ‘phone-numbers’. Totally different matter. Unless you know who does it, there isn’t anything you can do.
But that probably doesn’t stop the abuser to register a new IP-ntp-server and start all over again.

How on earth are you going to prevent this? If you know that, you know how to stop call-centers, spammers and phishers.

So far nobody managed to do that. Not even the police, banks, governments, DKIM, SPF etc.