capy, I'd highly suggest reading the full article on the DRDOS attack, it uses an overload of REAL traffic there really is no way to just put up a patch that says ok these packets are bad. With a DRDOS attack, it sends SYN (maybe SYN/ACK can't remember) packets from thousands of routers where the return IP is spoofed to be the victim server. So when the router goes to respond they all respond back to the victim. If you filter out those routers, or if you filter out that port you will be knocking out ALL traffic including legitimate traffic.. which is no better than taking it on the chin because either way the bad guy wins and your site is down