Beware: Network Time Protocol (NTP) Amplification Attacks, and Microsoft Security Bulletin Advance Notification.
Our security note this evening includes: Network Time
Protocol (NTP) Amplification Attacks, and Microsoft Security
Bulletin Advance Notification.
As usual Connectikpeople.co is there when it required. Dear professionals, a vulnerability in the "monlist" feature of NTP can allow remote
attackers to cause distributed denial of service attack (DDoS) via forged
requests. US-CERT and the Canadian Cyber Incident Response Center (CCIRC) have
both observed active use of this attack vector in recent DDoS attacks.
Therefore Connectikpeople.co encourages users and administrators to review
the CCIRC document as well as US-CERT Vulnerability Note VU#348126 for more
information.Regarding Microsoft, the company has issued a Security Bulletin Advance Notification indicating its January 2014 release will contain four bulletins. These bulletins will have the severity rating of important and will be for Microsoft Office, Server Software, Windows, and Microsoft Dynamics AX.