UDP 67
Synopsis
- UDP port 67 is used by DHCP/BOOTP servers to receive client requests; real implementations include ISC DHCP Server (dhcpd), Kea DHCP, Microsoft Windows Server DHCP, dnsmasq (used by OpenWrt, EdgeOS, and many home routers), and router-embedded servers on Cisco IOS/IOS-XE, MikroTik RouterOS, and Juniper Junos.
- Network appliances providing DHCP, such as Infoblox NIOS and BlueCat, also listen on UDP 67.
- DHCP relay agents like ISC dhcrelay, Kea DHCP relay, and Cisco IOS “ip helper-address” forward client broadcasts to servers on UDP 67.
- PXE/network boot environments rely on DHCP over UDP 67 for discovery; examples include FOG Project and Windows Deployment Services deployments where the Windows DHCP service handles the initial requests.
- Associated exploitation: rogue DHCP servers and DHCP starvation/spoofing attacks (e.g., with Yersinia or DHCPig) can hijack DNS/default gateway settings or exhaust address pools.
Observed activity
Last 30 days
Detailed chart