NTP Amplification Attacks Explained: Reflection and DDoS for Security+
An NTP amplification attack is a distributed denial-of-service technique that turns public time servers into unwitting weapons. It is the textbook example of a reflection and amplification attack, and that is exactly why exams like it. The attacker sends a small request with a forged source address. The server sends a much larger reply to the victim. Repeat across thousands of servers and the victim drowns in traffic that never came from the attacker. Why NTP Works So Well for This Three properties combine, and all three are needed. NTP runs over UDP, on port 123. UDP is connectionless — there is no handshake, so the server has no way to confirm that the address in the request is the address that sent it. That is what makes spoofing possible, and spoofing is what makes reflection possible. NTP is everywhere and rarely blocked. Time synchronization is essential infrastructure; Kerberos authentication, certificate validation, and log correlation all break when clocks drift...