Port 123: Network Time Protocol
UDP port 123 is used by the Network Time Protocol (NTP). RFC 5905 defines NTP packets as UDP datagrams and names 123 as the NTP port assigned by IANA. Servers and clients use it to synchronize clocks, and the Windows Time service also runs NTP on UDP 123.
Port Details
Security Exposure
ntpd versions before 4.2.7 answer the monlist command with a list of the last 600 IP addresses that connected to the server, which attackers abuse with spoofed requests to amplify traffic toward a victim (CVE-2013-5211, CISA alert TA14-013A). CISA lists NTP's bandwidth amplification factor as 556.9. RFC 8633 warns that NTP control (Mode 6) queries are also a vector for amplification attacks when left open.
Hardening
- +Upgrade ntpd to version 4.2.7 or later, or disable monlist with the noquery restriction, as CISA advises.
- +Use restrict default with nomodify, notrap, nopeer, and noquery, as shown in RFC 8633.
- +Block NTP control message queries from outside the organization on public-facing servers (RFC 8633).
- +Apply BCP 38 source address validation to reduce spoofed traffic.
Monitoring
Watch for NTP responses much larger than their requests, high response volumes to a single address, and Mode 6 or Mode 7 queries from outside the network.
Tools for Auditing and Monitoring NTP
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Frequently Asked Questions
Is NTP TCP or UDP?→
NTP uses UDP port 123. IANA also registers TCP 123, but RFC 5905 defines NTP packets as UDP datagrams.
What is an NTP amplification attack?→
Attackers send small spoofed queries such as monlist to open NTP servers, which send much larger responses to the victim (CISA TA14-013A).
Sources
- IANA Service Name and Transport Protocol Port Number Registry (port 123)
- RFC 5905: Network Time Protocol Version 4: Protocol and Algorithms Specification
- RFC 8633: Network Time Protocol Best Current Practices
- CISA Alert TA14-013A: NTP Amplification Attacks Using CVE-2013-5211
- CISA Alert TA14-017A: UDP-Based Amplification Attacks
- Microsoft Learn: Service overview and network port requirements for Windows
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 123 is not guaranteed to be NTP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).