108
Summary
- // if you see it open
- No CVE tied to the port itself and no primary-source threat data found this pass. One low-authority secondary aggregator (auditmypc.com) asserts an unspecified historical trojan/virus association; undated and uncorroborated — treated as unverified, not asserted as fact. A responsive port 108 on a modern host is anomalous and worth investigating.
- // analyst note
- A responsive port 108 today is anomalous — the registration is legacy SNA-gateway and rarely legitimately open on modern hosts; investigate rather than assume a normal service.
About port 108/tcp.
Port 108/tcp is registered with IANA as snagas with the description "SNA Gateway Access Server," contact Kevin Murphy, and a blank reference field. It is dual-registered on both TCP and UDP: the IANA Service Name and Transport Protocol Port Number Registry carries identical snagas entries for 108/tcp and 108/udp. The name points at IBM's Systems Network Architecture (SNA), the mainframe networking stack that predates and coexisted with TCP/IP: an "SNA Gateway Access Server" is the kind of product that bridged legacy SNA/mainframe traffic (3270 terminal sessions and LU-to-LU conversations) onto TCP/IP networks during the 1990s and 2000s. The registration cites a person contact rather than an RFC, so no protocol specification is published for it — the IANA reference field is legitimately blank, and no RFC should be invented to fill it. For an analyst this is a legacy, niche assignment: it is not part of any modern mainstream protocol stack, and no currently-maintained software product could be verified as the active implementation binding to this port today. Port 108 sits in the well-known range (0–1023), so it is swept by any full 1–65535 scan even though it is absent from Nmap's default top-1000. The nmap-services dataset records an observed open-frequency of approximately 0.000013 for 108/tcp — the lowest nonzero step it carries — while no authoritative dated Shodan/Censys exposure counts and no CVE tied to the port itself were found in this pass; one low-authority secondary aggregator asserts an unspecified historical trojan/virus association, but that claim is undated and uncorroborated against any primary threat-intel source, so it should be treated as unverified rather than asserted as fact.
- IANA assignment
snagas— "SNA Gateway Access Server"; reference (blank — no RFC cited in IANA registry); contact Kevin Murphy; dual-registered 108/tcp + 108/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (local cached CSV rows 285/286; live XML)- Range class
- well-known (0–1023) [Confirmed]
- IANA reference / RFC
- blank — the assignment cites a person contact (Kevin Murphy), not an RFC; no specification is published [Confirmed] — IANA XML
- Registration / modification date
- Unknown — all trailing columns (Registration Date, Modification Date, Reference, Service Code, Unauthorized Use Reported, Assignment Notes) are blank in the registry CSV; not fabricated [Confirmed] — IANA registry CSV
- Prevalence / exposure
- nmap-services observed open-frequency 108/tcp ≈ 0.000013 — the dataset's lowest nonzero step [Confirmed] — nmap-services dataset; sibling 108/udp ≈ 0.000494, some thirty-eight times higher. Well-known low port swept by any full 1–65535 scan (not in Nmap default top-1000); no authoritative dated Shodan/Censys exposure counts or port-specific CVE found this pass [Unknown]
- Related ports
- legacy IBM SNA / mainframe-access assignments in the well-known range
Primary use
SNA (IBM Systems Network Architecture) gateway access — products bridging legacy SNA/mainframe traffic (e.g. 3270/SNA-over-IP) onto TCP/IP networks; legacy/niche registration [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml, https://whatportis.com/ports/108_sna-gateway-access-server
Common software
Unknown — no currently-maintained product could be verified as the active implementation binding to this port; older SNA gateway software (IBM Communications Server / third-party SNA-IP gateway era) is the presumed historical context but no dated, sourced product reference was found [Unknown]
Security implications
one low-authority secondary aggregator (auditmypc.com) asserts an unspecified historical trojan/virus association; undated and uncorroborated against a primary source — treat as unverified, not fact
- Analyst note
- A responsive port 108 today is anomalous — the registration is legacy SNA-gateway and rarely legitimately open on modern hosts; investigate rather than assume a normal service.
About port 108/udp.
Port 108/udp is registered with IANA as snagas with the description "SNA Gateway Access Server," a person contact of Kevin Murphy, and a blank reference field. The assignment is dual-registered on both 108/tcp and 108/udp — the two registry rows are identical apart from the transport-protocol column — so the same service name applies whether the transport is TCP or UDP. As the registered name implies, snagas denotes a gateway/protocol-translation service that bridges IBM Systems Network Architecture (SNA) traffic onto TCP/IP networks; SNA is IBM's legacy networking stack from the mainframe and AS/400 era, and an "SNA gateway" is the general category of product that lets those legacy hosts interoperate with IP infrastructure. The registration is old and predates the modern registrant/organization convention, which is why the record carries an individual person's name rather than a sponsoring company. The IANA reference field is blank and no RFC is cited for this assignment, so it is left blank here rather than inventing one. For an analyst, port 108 is primarily a legacy-service identifier: seeing it in a registry lookup tells you the number was reserved for SNA-to-IP gateway software, but the registry itself names no specific vendor product. One third-party port-lookup site notes a historical association between port 108 (both transports) and past Trojan/backdoor activity, i.e. malware that reused this port number for command-and-control; that claim is community-sourced, names no specific malware family, sample, or date, and could not be corroborated against a primary security source, so it is recorded as a low-confidence historical note rather than a verified current threat. On scan prevalence, the nmap-services dataset records snagas on 108/udp with an open-frequency of 0.000494 — roughly five hundredths of one percent of sampled hosts, against 0.000013 for 108/tcp — so the port is rarely found open, though the UDP figure carries the usual open|filtered caveat noted below.
- IANA assignment
snagas— "SNA Gateway Access Server"; reference (blank — no RFC cited in IANA registry); person contact Kevin Murphy; dual-registered 108/tcp + 108/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry; local registry copythe IANA Service Name and Transport Protocol Port Number Registry(lines 285-286)- Range class
- well-known (0–1023)
- Prevalence (nmap-services open-frequency)
- 0.000494 for
snagason 108/udp — about 0.05% of sampled hosts, against 0.000013 on 108/tcp; this is nmap's scan-sample corpus rather than a live feed, and the UDP figure is subject to the open|filtered caveat below [Confirmed] — nmap-services dataset - Related ports
- legacy IBM/SNA service cluster; the same well-known range neighbors
Primary use
gateway/protocol-translation service bridging IBM SNA (mainframe/AS-400-era) traffic onto TCP/IP networks
Common software/vendors
Unknown — the registry names no specific vendor product, and no primary vendor manual (e.g. an IBM/Microsoft SNA gateway product) was verified in this pass to confirm which software listens on 108/udp [Unknown]
Security implications
one third-party port-lookup site associates port 108 (tcp+udp) with historical Trojan/backdoor use; no malware family, sample, or date is cited and it is not corroborated by a primary source — treat as a general low-confidence historical note
Typically seen on
legacy IBM SNA-to-IP gateway environments (by the registration name); no verified current deployment sourced
- UDP scanning caveat (generic, not specific to 108)
- UDP port state is typically inferred from the absence of an ICMP port-unreachable reply, which yields frequent false positives/negatives — treat 108/udp "open" results cautiously
- Analyst note
- In a registry lookup, 108 signals a reserved SNA-gateway service name with a blank reference and no named vendor; the malware association is unverified community lore, so weigh it accordingly.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| snagas | UDP | SNA Gateway Access Server | 0.05% |
| snagas | TCP | SNA Gateway Access Server | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.