看板FB_security
标 题UNS: Re: NTP security hole CVE-2013-5211?
发信站NCTU CS FreeBSD Server (Fri Jan 10 06:14:43 2014)
转信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
<<On Thu, 09 Jan 2014 21:08:41 +0700, Eugene Grosbein <
[email protected]> said:
> Other than updating ntpd, you can filter out requests to 'monlist' command
> with 'restrict ... noquery' option that disables some queries for
> the internal ntpd status, including 'monlist'.
For a "pure" client, I would suggest "restrict default ignore" ought
to be the norm. (Followed by entries to unrestrict localhost over v4
and v6.)
-GAWollman
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"