The number of vulnerable NTP servers has declined rapidly but still remains high

June 26, 2014

A vulnerability in the Network Time Protocol (NTP) started to be used for amplification of DDoS attacks massively since the end of 2013. It allowed the attacker to amplify the attack more than 700 times in ideal conditions. Security company NSFOCUS which monitors the vulnerable NTP servers worldwide has found out that the number of vulnerable NTP servers that may be used for such attack has declined rapidly to about 17,000 from almost half million in December 2013. On the other hand the number of servers capable of highest multiplication of attacks remains almost unchanged. That still allows attackers to launch DDoS attacks of gigantic volume.

