Hi there all,
In the hope of posting this in the correct category/community.
Crawling my logs recently, i’ve found some strange replies on DNS queries towards X.centos.pool.ntp.org.
Here is one example:
Date/Time 02-05 08:34
Device Time 2020-02-05 08:34:04
Domain Name 0.centos.pool.ntp.org
Event Time 1580888044259527691
IP Address 184.108.40.206,220.127.116.11,18.104.22.168,22.214.171.124
Query Type Value1
Time Stamp 2020-02-05 08:34:08
Time Zone +0100
I’ve matched pretty all my centos boxes getting the same answers (ip addresses in return to the query) between 05.02.2020 and 07.02.2020.
The issue is that the 185.220.101.xx IP’s returned are Tor.Exit.Nodes. Which i thought was, hum, weird.
If anyone could comment or acknowledge any issues @ntp.org DNS wise?