RE: WINDOWS XP NTP

From: David Schwartz (davids@webmaster.com)
Date: 08/21/01


From: "David Schwartz" <davids@webmaster.com>
To: "John Galt" <galt@inconnu.isu.edu>, "Dino" <slayer67@apk.net>
Subject: RE: WINDOWS XP NTP
Date: Tue, 21 Aug 2001 14:58:13 -0700
Message-ID: <NOEJJDACGOHCKNCOGFOMKEMGDFAA.davids@webmaster.com>


> locutus#ntptrace time.windows.com
> time.windows.com: stratum 2, offset 0.002825, synch distance 0.06490
> time.nist.gov: stratum 1, offset 0.004652, synch distance
> 0.00000, refid 'ACTS'
>
> Locutus is most definitely not a windows XP box :)
>
> I'm still guessing that any and all NTP 'sploits are prefectly valid for
> Win XP, and even more so, since there is a default attack vector. You can
> get substantial coverage with a script that forges an NTP packet from
> time.windows.com (207.46.228.33 according to my dig, but it's
> non-authoritative...) The fun part is they're .60 seconds off NIST:
> pathetic for a stratum 2.

        Riddle me this: If your machine's offset to time.windows.com was 2.8
milliseconds and your machine's offset to time.nist.gov was 4.6
milliseconds, how can time.windows.com be off by 600 milliseconds? My tests
show pretty much conclusively that time.windows.com is off from UTC by 10
milliseconds or less and off from time.nist.gov by 4 milliseconds or less.

        DS



Relevant Pages

  • Re: OS recomendations for stratum 2 clocks
    ... Right now I have a problem with a closed network where the computer clocks sometimes get ten or twenty milliseconds out of synch, even though they usually stay within a millisecond or so. ... The problem is that other realtime activities in the various servers is kicking the NTP daemons sidewise during heavy system load. ... NTP cannot tell this from real transport delay, randomly asymmetrical delay at that, so a lot of really bad samples eventually leak through the median filter and corrupt NTP's notion of the time offset to the master clocks. ...
    (comp.protocols.time.ntp)
  • Re: Slow sychronization
    ... I am running a new version of the NTP daemon, version 4.2.4p6, on a Linux ... offset of about 30 milliseconds. ... This offset will increase to about 50 ...
    (comp.protocols.time.ntp)
  • Re: Proposed NTP solution for a network
    ... NTP does this ONLY when the time is off by 128 milliseconds or more. ... NTP is that far off, other than at startup, something is badly wrong ... to be stepped by 1s back and forth (see bug #1110). ...
    (comp.protocols.time.ntp)
  • Re: Packet timestamps when using Windows-7/Vista
    ... I've written a small program which sends some SNTP packets to various NTP ... This looks like the clock interpolation works pretty good here. ... and there also needs to be a conversion from one tick rate to ... Windows value based on a one millisecond timer. ...
    (comp.protocols.time.ntp)
  • Re: Packet timestamps when using Windows-7/Vista
    ... I've written a small program which sends some SNTP packets to various NTP ... This looks like the clock interpolation works pretty good here. ... time between packet reception and transmission of a reply. ... Windows value based on a one millisecond timer. ...
    (comp.protocols.time.ntp)