Live NTP Clock Skew, Stratum & monlist Enumeration Inspector (2026)

Measure local clock skew, decode 48-byte RFC 5905 NTP packet headers, calculate UDP Mode 6 (`readvar`) & Mode 7 (`monlist`) DDoS amplification factors, and generate hardened `chrony.conf` / `ntpd` NTS configs.

Live NTP Clock Skew, Stratum & monlist Enumeration Inspector — Interactive Console
Runs locally in your browser • Instant output
Stratum 2: Secondary Enterprise/ISP Time Server syncing via UDP/123 hierarchy
HEALTHY: Clock offset within sub-second enterprise tolerance.
Simulated `ntpq -c rv` Mode 6 Packet Response
associd=0 status=0615 leap_none, sync_ntp, 1 event, clock_sync,
version="ntpd 4.2.8p15@1.3728-o", processor="x86_64",
system="Linux/5.15.0-112-generic", leap=00, stratum=2,
precision=-23, rootdelay=12.412, rootdisp=24.890, refid=192.0.2.1,
offset=14.200, jitter=1.402
Nmap UDP/123 Recon & Hardening Config
# 1. Nmap UDP/123 Mode 6 (readvar banner leak) & Mode 7 (monlist amplification) Audit
nmap -sU -p 123 --script ntp-info,ntp-monlist ntp.example.org

# 2. Query NTP Control Mode 6 System Variables (OS, ntpd version, Stratum, RefID)
ntpq -c rv ntp.example.org
ntpq -c peers ntp.example.org

# 3. Chrony Modern CLI Source & Drift Verification
chronyc sources -v
chronyc tracking

# 4. Hardened /etc/ntp.conf Remediation (Block Mode 6 & Mode 7 Amplification)
restrict default kod nomodify notrap nopeer noquery
restrict -6 default kod nomodify notrap nopeer noquery
disable monitor
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Live NTP Clock Skew, Stratum & monlist Enumeration Inspector](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/ntp-stratum-clock-drift-enumeration-inspector/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/ntp-stratum-clock-drift-enumeration-inspector/">Live NTP Clock Skew, Stratum & monlist Enumeration Inspector — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: Live NTP Clock Skew, Stratum & monlist Enumeration Inspector

Quick Answer & 2026 Technical Summary (ntp enumeration clock drift checker)Updated 2026 Standard

When an NTP server allows unrestricted Mode 6 control queries (`ntpq -c rv <target>`), it returns internal system variables including the exact NTP daemon version, operating system (`system="Linux/5.15.0-x86_64"`), CPU architecture (`processor="x86_64"`), jitter, clock offset, and upstream reference server IP. Use this interactive ntp enumeration clock drift checker above to test ntp mode 6 readvar monlist scanner, ntp amplification factor calculator, and kerberos totp clock skew validator locally in your browser with zero server uploads.

Target Keyword Spec: ntp enumeration clock drift checker | Modules: NTP Mode 6 (readvar) & Mode 7 (monlist) Exposure Analyzer • Kerberos, TOTP (RFC 6238) & TLS Clock Drift Impact Calculator • RFC 5905 48-Byte NTP Packet Header Bitfield Visualizer
Primary Focus: ntp enumeration clock drift checker
Core Capability: ntp mode 6 readvar monlist scanner
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
NTP Mode 6 (readvar) & Mode 7 (monlist) Exposure Analyzerntp mode 6 readvar monlist scannerParse `ntpq -c rv` and `ntpdc -n -c monlist` outputs to flag OS kernel disc...External Penetration Testing & UDP Port 123 Reconnaissance
Kerberos, TOTP (RFC 6238) & TLS Clock Drift Impact Calculatorntp amplification factor calculatorEvaluate how milliseconds or minutes of clock skew break 30-second TOTP MFA...Active Directory Kerberos & MFA Authentication Troubleshooting
RFC 5905 48-Byte NTP Packet Header Bitfield Visualizerkerberos totp clock skew validatorInspect Leap Indicator (LI), Version Number (VN), Mode (Client/Server/Contr...Securing Edge Time Servers with Network Time Security (NTS)
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

What is NTP Enumeration & Network Time Security?

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Live NTP Clock Skew, Stratum & monlist Enumeration Inspector

01

Select an NTP Diagnostic Mode or Paste `ntpq -c rv` Output

Load a realistic vulnerable `ntpq` / `monlist` scan output, adjust the clock drift slider, or inspect the RFC 5905 packet structure.

02

Audit Information Disclosure & DDoS Amplification Vectors

Check whether the target NTP response leaks `system`, `processor`, `version`, or recent client IP addresses via Mode 6/7 control queries.

03

Simulate Clock Skew Impact on Auth & Cryptography

Test how a specific drift offset (ms to hours) impacts TOTP 2FA codes, Kerberos v5 tickets, OCSP stapling, and AWS SigV4 API requests.

04

Generate Hardened `chrony.conf` or `ntp.conf` Rules

Copy the generated configuration restricting control queries to loopback (`127.0.0.1` / `::1`) and enabling NTS encryption.

Key Capabilities & Technical Architecture

NTP Mode 6 (readvar) & Mode 7 (monlist) Exposure Analyzer

Parse `ntpq -c rv` and `ntpdc -n -c monlist` outputs to flag OS kernel disclosure, internal peer IP leakage, and 556.9x UDP reflection DDoS amplification risks.

Kerberos, TOTP (RFC 6238) & TLS Clock Drift Impact Calculator

Evaluate how milliseconds or minutes of clock skew break 30-second TOTP MFA windows, Kerberos 5-minute ticket tolerances (`KRB_AP_ERR_SKEW`), and distributed Raft logs.

RFC 5905 48-Byte NTP Packet Header Bitfield Visualizer

Inspect Leap Indicator (LI), Version Number (VN), Mode (Client/Server/Control/Private), Stratum (0–16), Poll Interval, Precision, Root Delay, and Reference Timestamp.

Hardened Chrony, systemd-timesyncd & NTS (RFC 8915) Generator

Generate copy-ready `chrony.conf` and `ntp.conf` policies with `noquery`, `nomodify`, `notrap`, rate limiting (`kod`), and authenticated Network Time Security (NTS).

Practical Use Cases

External Penetration Testing & UDP Port 123 Reconnaissance

Understand what an exposed NTP daemon reveals during `nmap -sU -p 123 --script ntp-info,ntp-monlist` scans—including exact Linux/BSD kernel versions and internal subnet peers.

Active Directory Kerberos & MFA Authentication Troubleshooting

Diagnose intermittent `KRB_AP_ERR_SKEW` domain login failures or rejected 6-digit TOTP codes caused by hypervisor VM clock drift across Stratum tiers.

Securing Edge Time Servers with Network Time Security (NTS)

Migrate legacy unauthenticated UDP 123 configurations to TLS 1.3-bootstrapped NTS (`time.cloudflare.com`, `nts.netnod.se`) to prevent MITM time-shifting attacks.

Frequently Asked Questions (FAQs)

What information does NTP Mode 6 (`readvar` / `rv`) leak to attackers?+

When an NTP server allows unrestricted Mode 6 control queries (`ntpq -c rv <target>`), it returns internal system variables including the exact NTP daemon version, operating system (`system="Linux/5.15.0-x86_64"`), CPU architecture (`processor="x86_64"`), jitter, clock offset, and upstream reference server IP.

Why is NTP `monlist` (Mode 7) one of the most dangerous DDoS amplification vectors?+

The legacy `monlist` command in `ntpd` (prior to v4.2.7p26) returns a list of the last 600 client IP addresses that queried the time server. Because UDP is connectionless, an attacker can send a tiny 234-byte spoofed request with the victim's source IP and trigger up to 556.9x bandwidth amplification back at the victim.

What do NTP Stratum levels (Stratum 0 through 16) mean?+

Stratum 0 represents hardware reference clocks (cesium/rubidium atomic clocks, GPS GNSS receivers) directly attached via PPS serial lines. Stratum 1 servers attach directly to Stratum 0 hardware. Stratum 2 servers sync over the network from Stratum 1, and so on up to Stratum 15. Stratum 16 indicates an unsynchronized clock.

How could an attacker exploit unauthenticated NTP to break HTTPS or HSTS?+

If a man-in-the-middle (MITM) attacker spoofs unauthenticated UDP port 123 responses, they can roll a victim's system clock backward to make revoked or expired X.509 certificates appear valid, or roll the clock forward into the future to expire HSTS (`Strict-Transport-Security`) max-age pins and DNSSEC RRSIG signatures.

How does Network Time Security (NTS, RFC 8915) secure NTP?+

NTS splits time synchronization into two phases: first, an NTS Key Establishment (NTS-KE) handshake over TCP port 4460 using TLS 1.3 to negotiate AEAD keys and opaque cookies; second, authenticated NTP UDP packets on port 123 using those AEAD extension fields without sacrificing nanosecond timestamp precision.