UDP Port 68 – DHCP Client (Dynamic Host Configuration Protocol)

UDP Port 68 – DHCP Client (Dynamic Host Configuration Protocol)

About UDP Port 68

Port 68 carries the IANA assignment for bootpc. The IANA description reads: ‘Bootstrap Protocol Client’. This port appears in 5 IDS rules and does not have notable malware activity indicators in our data.

IDS Rule References

5 IDS / security rules reference UDP port 68. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.

Rule categories (top 2): attempted-admin (3), attempted-user (2).

Sample rule descriptions for UDP port 68:

  • OS-OTHER Malicious DHCP server bash environment variable injection attempt
  • OS-LINUX Red Hat NetworkManager DHCP client command injection attempt
  • OS-LINUX Red Hat NetworkManager DHCP client command injection attempt
  • ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DHCP ACK
  • ET EXPLOIT DynoRoot DHCP – Client Command Injection

Data Sources

This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and Snort Community Rules (GPLv2).

© 2002-2026 AuditMyPC.com