logoalt Hacker News

Eridrusyesterday at 5:25 PM0 repliesview on HN

Yeah, I think this is misclassification based on UDP port.

If you take their random source ports (21,925), ~0.004% come from any single port, which lines up with what they said was "Other" traffic. The numbers don't quite work out right, but it seems like its within a factor of 2, so I wouldn't be surprised if it was something like udp source/dest port = 17 => QOTD.