nanog mailing list archives

Re: where to go to understand DDoS attack vector


From: Brian Rak <brak () gameservers com>
Date: Tue, 26 Aug 2014 20:37:51 -0400


On 8/26/2014 8:28 PM, Larry Sheldon wrote:
On 8/26/2014 08:31, Roland Dobbins wrote:

On Aug 26, 2014, at 8:26 PM, Stephen Satchell <list () satchell net> wrote:

qotd            17/udp          quote

No, that's the protocol number - 17 is UDP - not the port number.


Really?

http://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers

udp DID used to be protocol 17, but it is a fact that quotd runs on udp port 17.


Yes, he is correct.  This is not UDP port 17.

> 8:33:58.482193 IP (tos 0x0, ttl 56, id 0, offset 0, flags [DF], proto UDP (17), length 29) x.x.x.x.2072 > x.x.x.x.27015: UDP, length 1

Protocol: UDP (IP protocol 17)
Source Port: 2072
Dest Port: 27015

What protocol is UDP now, if it's not 17?


Current thread: