107
Summary
- // if you see it open
- As a Telnet-family remote-login protocol, rtelnet would inherit Telnet's lack of transport encryption (credentials and data in plaintext) wherever implemented and exposed; SSH is the modern replacement for Telnet-family protocols. No port-107-specific CVE, exposure statistic, or dated advisory was found to cite.
- // analyst note
- A responsive port 107 is statistically rare and legacy; treat as a fingerprinting/anomaly signal. Its RFC 818 lineage is real, but the IANA Reference column is genuinely blank — do not fabricate an RFC citation into that field.
About port 107/tcp.
Port 107/tcp is registered with IANA as rtelnet with the description "Remote Telnet Service," contact/assignee Jon Postel, and a blank reference field in the registry's own Reference column (dual-registered on TCP and UDP). The service is specified in RFC 818, "The Remote User Telnet Service" (J. Postel, November 1982): rather than a user's terminal reaching a host's own Telnet listener on port 23, a machine acting on the user's behalf opens a connection to port 107 on a remote server and runs the Telnet protocol across it, effectively offering Telnet-style network-virtual-terminal access as a service one host can provide to another. It is a legacy, application-level protocol distinct from standard Telnet on port 23, and it predates the modern registry's formal Reference-column convention — which is why IANA lists only Jon Postel as the contact and leaves the Reference field blank even though a real, citable RFC exists. No modern software implementations, daemons, or client tools for rtelnet on port 107 could be verified beyond the 1982 specification; generic port-lookup directory sites merely restate the IANA entry and were excluded as sources. Likewise, no port-107-specific exposure statistics (Shodan/Censys), scanning-campaign reports, or CVEs were found, so those remain Unknown rather than inferred. As a Telnet-family remote-login protocol, rtelnet would inherit Telnet's lack of transport encryption — credentials and data in plaintext — anywhere it were actually implemented and exposed, but no dated incident or advisory tied specifically to this port exists to cite. For an analyst, a responsive port 107 is a rare legacy signal worth investigating rather than a routine service.
- IANA assignment
rtelnet— "Remote Telnet Service"; reference (blank in the IANA registry Reference column — only Jon Postel cited); contact/assignee Jon Postel; dual-registered 107/tcp + 107/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (registry CSV + live XML)- Range class
- well-known (0–1023) [Confirmed]
- Related ports
- standard Telnet 23/tcp; the small legacy remote-access family
Primary use
historical remote-login / network-virtual-terminal service — a host opens a connection to port 107 to run the Telnet protocol to a remote server on a user's behalf; specified in RFC 818 (1982), distinct from standard Telnet on port 23
Common software / implementations
Unknown — no current or historical rtelnet daemons, clients, or vendor products verifiable beyond the 1982 RFC [Unknown]
Exposure / scanning / CVEs
Unknown — no port-107-specific Shodan/Censys statistics, scanning reports, or CVE entries found; secondary port-lookup directories restate the IANA entry without dated primary data [Unknown]
Security implications
As a Telnet-family protocol, rtelnet would carry credentials/data in plaintext (no transport encryption) wherever implemented and exposed; modern practice replaces Telnet-family protocols with SSH. No port-107-specific dated advisory or CVE found to attribute
Typically seen on
legacy / rare; an open port 107 today is an anomaly worth investigating rather than a normal service
- Associated specification
- RFC 818, "The Remote User Telnet Service" (J. Postel, November 1982). A genuine, dated RFC associated with this port; note the IANA registry's own Reference field for 107 is nonetheless blank [Confirmed] — RFC-Editor / IETF Datatracker
- Analyst note
- A responsive port 107 is statistically rare and legacy; treat as a fingerprinting/anomaly signal. Its RFC 818 lineage is real, but the IANA Reference column is genuinely blank — do not fabricate an RFC citation into that field.
About port 107/udp.
Port 107/udp is registered with IANA as rtelnet with the description "Remote Telnet Service," assignee Jon Postel, and a blank reference field. The registration is dual-listed: TCP/107 carries the identical service name, description, and assignee, so rtelnet reserves both the TCP and UDP entries at 107. No RFC is cited in the IANA registry for this assignment, and IANA publishes no assignment date on the entry — both the Reference and any date field are honestly blank rather than filled with an invented value. The name describes a legacy remote-login / command-line service positioned as an alternate or extension to standard Telnet (TCP/UDP 23); it predates modern encrypted remote-access protocols. In practice rtelnet is effectively obsolete: no current, actively maintained software was found implementing it in production, and Telnet-family plaintext remote-login has been broadly superseded by SSH (TCP 22) because Telnet transmits credentials and session data without encryption. For an analyst, an open UDP/107 is a rarity worth investigating rather than a normal service. No CVEs or active exploitation campaigns targeting UDP/107 were found; a legacy port-to-malware cross-reference list associates port 107 historically with a "Skun" trojan/virus family, but that is a low-confidence aggregator artifact — historical trivia, not a current threat indicator. As with any exposed UDP listener, a responsive rtelnet service would be a scanning and reconnaissance target and, if it behaves like plaintext Telnet, would carry the same credential-interception risk.
- IANA assignment
rtelnet— "Remote Telnet Service"; reference (blank — no RFC cited in IANA registry); assignee Jon Postel; dual-registered 107/tcp + 107/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry; local registry file the IANA Service Name and Transport Protocol Port Number Registry lines 283 (TCP) and 284 (UDP)- Range class
- well-known (0–1023) [Confirmed]
- Assignment date
- none published by IANA on this entry [Unknown] — IANA registry (no date column value)
- Related ports
- Telnet 23/tcp+udp; contrast SSH 22/tcp (encrypted replacement)
Primary use
legacy remote-login / command-line service positioned as an alternate or extension to standard Telnet (TCP/UDP 23), predating modern encrypted remote access [Likely] — IANA registry description "Remote Telnet Service" (no defining RFC); secondary port directories describe it as a Telnet extension
Common software
none verifiable — no current, actively maintained implementation found [Unknown]
Security implications
no CVEs or active exploitation found for UDP/107; a legacy port-to-malware list ties port 107 to a "Skun" trojan/virus family (low-confidence aggregator artifact, historical not current); an exposed plaintext rtelnet listener would carry Telnet-style credential-interception risk and be a recon target
Typically seen on
not associated with any current mainstream software; a responsive UDP/107 is an anomaly worth investigating
- Current real-world use
- effectively obsolete; Telnet-family plaintext remote login broadly superseded by SSH (TCP 22) for lack of encryption [Likely] — auditmypc.com port-107 note
- Analyst note
- An open UDP/107 is statistically rare and not tied to known active software — treat as an anomaly, decoy, or misconfiguration; legitimate current use is unlikely.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| rtelnet | UDP | Remote Telnet Service | 0.05% |
| rtelnet | TCP | Remote Telnet | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.