80/udp floods?

Scott Call scall at devolution.com
Wed Feb 18 10:45:14 UTC 2004


I apologize for the potentially obvious question, but I've been through
sf, google, etc and can't find anything.

I have a customer that is currently getting several hundred thousand
packets per second sent to them on 80/udp.  /etc/services lists 80/udp as
IANA assigned for http but I've never seen a udp implementation of http so
I'm assuming it's a sneaky DOS/DDOS of some kind.

ACL's seem to work to catch it but I'm curious if anyone has seen this
specific attack (80/udp) before.

Thanks
-Scott


-- 
Scott Call	Router Geek, ATGi, home of $6.95 Prime Rib
I make the world a better place, I boycott Wal-Mart
VoIP incoming: +1 360-382-1814




More information about the NANOG mailing list