monlist command against NTP servers is being used to launch DDOS attacks.
ESXi 4.1 contains a vulnerability that can be used to create an amplification attack using the molist command in NTP.
If you’re using that version, you can mitigate the issue by editing
/etc/ntp.conf and adding
nopeer to the restrict line
restrict default kod nomodify notrap noquery nopeer
Once done, restart NTP with