r1 - 2009-06-13 - 03:39:39 - HarlanStennYou are here: NTP >  Main Web > CodeAudit
NTP users are strongly urged to take immediate action to ensure that their NTP daemons are not susceptible to use in a distributed denial-of-service (DDoS) attack. Please also take this opportunity to defeat denial-of-service attacks by implementing ingress and Egress filtering through BCP38.

ntp-4.2.8p3 was released on 29 June 2015, and addresses leap-second issues and a minor security issue.

Please see the NTP Security Notice for vulnerability and mitigation details.

Are you using Autokey in production? If so, please contact Harlan - he's got some questions for you.

Code Audit

The NTP Codebase undergoes security and defect audits from a number of sources, including:

Area By Dates
Protocol and core code David L. Mills 1985 - present
codebase http://www.coverity.com Mar 2006 - present
codebase http://calysto.org Jun 2007 - Sep 2008
codebase http://veracode.com Feb 2009 - present

Additionally, a number of project developers and interested parties in the Internet Community routinely scan the code looking for problems.

Edit | WYSIWYG | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r1 | More topic actions
 
SSL security by CAcert
Get the CAcert Root Certificate
This site is powered by the TWiki collaboration platform
IPv6 Ready
Copyright & 1999-2015 by the contributing authors. All material on this collaboration platform is the property of the contributing authors. Ideas, requests, problems regarding the site? Send feedback