In a DDoS amplification attack, say NTP flooding, an attacker uses a botnet network in order to query multiple NTP servers on port 123, spoofing the source address using the address of the victim/target.
To which port is the reflected traffic from these NTP servers sent? Does the attacker target a specific service on the victim host (chosen after the reconnaissance & scanning phases)? or, is he simply sending UDP traffic to the victim and doesn't care much about the port to which that traffic is being sent?
More generally, what are the ports involved in a DDoS amplification attack?