Attack/DoS

Perry E. Metzger perry at piermont.com
Thu Jun 4 03:38:24 UTC 1998


"Todd R. Stroup" writes:
> Don't know if it is just me.  But over the last 10 hours we have been
> seeing attacks on port 0 from port 0 (both tcp and udp) on several clients
> networks.  I have also seen the same attack on port udp 53(DNS). 
> 
> Anyone have any information on this?  

What do you mean by an "attack"? Are you being flooded? Are the
packets somehow "interesting"? Without details the information is
useless.

Port 0, btw, is not generally valid, and most proper TCP and UDP
implementations will just send an ICMP Unreachable back when they get
such a packet.

Perry



More information about the NANOG mailing list