UDP Port 68 – DHCP Client (Dynamic Host Configuration Protocol)
About UDP Port 68
Port 68 carries the IANA assignment for bootpc. The IANA description reads: ‘Bootstrap Protocol Client’. This port appears in 5 IDS rules and does not have notable malware activity indicators in our data.
IDS Rule References
5 IDS / security rules reference UDP port 68. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 2): attempted-admin (3), attempted-user (2).
Sample rule descriptions for UDP port 68:
- OS-OTHER Malicious DHCP server bash environment variable injection attempt
- OS-LINUX Red Hat NetworkManager DHCP client command injection attempt
- OS-LINUX Red Hat NetworkManager DHCP client command injection attempt
- ET EXPLOIT Possible CVE-2014-6271 exploit attempt via malicious DHCP ACK
- ET EXPLOIT DynoRoot DHCP – Client Command Injection
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and Snort Community Rules (GPLv2).
