Network port detail · UDP/TCP

134

Ingres-net
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No CVEs, malware families, or botnet associations specific to port 134 were found; low independent security research visibility on this port.
// analyst note
Treat 134/tcp as a formal-but-rarely-observed registration; don't assume its presence or absence tells you much about Ingres deployment without corroborating the dynamically-derived port range.
[ 01 ] — Context

About port 134/tcp.

Updated  ·  Confidence: Medium

Port 134/tcp is registered with IANA as ingres-net, described as "INGRES-NET Service," with assignee and contact both listed as [Mike_Berrow]. The Registration Date, Modification Date, IANA Reference, Service Code, and Assignment Notes fields are all blank in the IANA registry — this entry predates the era of fully-documented assignments, so those fields stay unrecorded here rather than being filled with a guessed date or invented RFC. The assignment is dual-registered: 134/udp carries the identical service name and description. Ingres is a relational database management system that originated as a research project at UC Berkeley in the 1970s and was later commercialized (through Ask Computer Systems, then Computer Associates/CA, and today Actian). "INGRES-NET" refers to the database's network communication layer for client-server connectivity between an Ingres client and a remote Ingres installation. Despite the fixed IANA assignment of port 134, community documentation on real-world Ingres deployments indicates that installations typically do not listen on port 134 itself; instead, Ingres derives an actual TCP listening port dynamically from the installation ID (the II_INSTALLATION setting), producing ports in roughly the 16904–30152 range (for example, the default installation ID "II" commonly maps to TCP 21064). This means the formal IANA registration and the port actually observed in the field frequently diverge — worth flagging for anyone using port 134 as a fingerprint. No CVEs, malware families, or notable internet-scan prevalence data specific to port 134 were found; this port sees little independent security research and no meaningful exploitation history has been documented, so its threat profile is treated as low-visibility rather than confirmed-benign.

IANA assignment
ingres-net — "INGRES-NET Service"; reference (blank — no RFC cited in IANA registry); assignee/contact [Mike_Berrow]; dual-registered 134/tcp + 134/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)
Range class
well-known (0–1023)
Prevalence
no internet-scan prevalence figures (e.g., nmap-services frequency) were located for this port in this pass [Unknown]
Related ports
other database-service assignments in the well-known range; Ingres's own dynamically-assigned high ports (~16904–30152) are the more common real-world indicator [Likely]

Primary use

registered for the Ingres relational database's network communication service (INGRES/NET), historically used for client-server connectivity to Ingres DBMS installations

[Confirmed] — IANA registry

Other/unofficial uses

in practice, real Ingres installations commonly do not use fixed port 134 — the actual TCP port is derived from the installation ID (II_INSTALLATION), typically landing in the ~16904–30152 range (e.g., default install ID "II" → TCP 21064) [Likely] — https://ariel.its.unimelb.edu.au/~yuan/ingres/ingres_net_port.html, https://groups.google.com/d/topic/fa.ingres/nVbhN5MkLug

Security implications

no CVEs, malware, or botnet associations specific to port 134 were found; low research visibility rather than a confirmed absence of risk [Unknown]

Typically seen on

legacy/legacy-adjacent Ingres DBMS installations, where present at all; given the dynamic-port behavior above, an open 134/tcp is not a reliable indicator of an active Ingres service [Likely]

Analyst note
Treat 134/tcp as a formal-but-rarely-observed registration; don't assume its presence or absence tells you much about Ingres deployment without corroborating the dynamically-derived port range.
[ 02 ] — Context

About port 134/udp.

Updated  ·  Confidence: Medium

Port 134/udp is registered with IANA as ingres-net, described as "INGRES-NET Service," with assignee and contact both listed as Mike Berrow. The registry entry carries no RFC or standards-track reference — only that registrant contact name appears in the XML/CSV record, which is not itself a normative citation, so the Reference field is left blank rather than filled with an invented RFC number. The same name and description are dual-registered on 134/tcp, with identical assignee/contact and identically blank date, reference, and notes columns; nothing in the registry indicates when the assignment was made. The service refers to Ingres/Net, the network-communications layer of the Ingres relational database management system (originally Ingres Corporation, later CA-Ingres, now Actian Ingres / Actian X), which lets Ingres client tools reach a DBMS server on a remote host. This is an early-1990s-era System Port assignment, and modern Ingres/Actian documentation and community discussion describe current Ingres/Net installations actually communicating over a different, installation-ID-derived port range (commonly cited as roughly 21064–21071, the "II2"–"II7" ports), not literal port 134 — meaning the IANA reservation is a legacy label rather than a live description of how contemporary Ingres deployments are configured. SANS Internet Storm Center's port-134 dashboard shows only low-volume, sporadic scan traffic on both tcp and udp, consistent with routine internet-wide background noise rather than a targeted campaign, and lists no associated CVEs. Net effect: an obscure, largely inactive legacy database-service port that an analyst should treat as low-priority unless corroborated by other host context.

IANA assignment
ingres-net — "INGRES-NET Service"; assignee/contact Mike Berrow; dual-registered 134/tcp + 134/udp; Registration Date, Modification Date, Reference, Service Code, Unauthorized Use Reported, and Assignment Notes columns are all blank in the registry (confirmed blank, not a lookup failure) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry rows 345–346; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
IANA reference (RFC)
blank/Unknown — no RFC or standards-track document is cited in the registry entry; not inferred [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
Range class
registered (49?/well-known boundary — 134 falls in the well-known range, 0–1023)

Primary use

registered for Ingres/Net, the network-communications component of the Ingres RDBMS, allowing Ingres clients/tools to reach a DBMS server on another host

[Confirmed] — https://en.wikipedia.org/wiki/Ingres_(database); https://tldp.org/HOWTO/IngresII-HOWTO/net.html

Common software

Ingres RDBMS (Ingres Corporation / CA-Ingres / Actian Ingres / Actian X) — Ingres/Net communications server; no other mainstream software documented as using this port

[Likely] — https://en.wikipedia.org/wiki/Ingres_(database); https://tldp.org/HOWTO/IngresII-HOWTO/net.html

Security implications

low-priority/legacy port; maps to an obscure, largely inactive legacy database service rather than widely-deployed modern software; no confirmed malware/backdoor association; observed scanning is background-noise level

[Likely] — https://isc.sans.edu/data/port/134
Current real-world use
modern Ingres/Actian deployments' Ingres/Net component is documented as running over a different, installation-ID-derived port range (~21064–21071), not literal port 134, suggesting the port-134 IANA entry is a legacy naming/registration rather than a current operational description [Likely] — https://tldp.org/HOWTO/IngresII-HOWTO/net.html; https://fa.ingres.narkive.com/WlEKz2ZW/info-ingres-which-tcp-port-does-ingres-net-use-on-hpux; https://groups.google.com/g/fa.ingres/c/nVbhN5MkLug
Scanning/exposure notes
SANS ISC port-134 dashboard (tcp and udp) shows only sporadic, low-volume background scan traffic, no listed CVEs; a consumer port-lookup site (auditmypc.com) shows no current malware/trojan flag for UDP/134, though its "flagged in the past" disclaimer reads as generic boilerplate reused across many port pages rather than port-134-specific evidence
[Likely] — https://isc.sans.edu/data/port/134; https://www.auditmypc.com/udp-port-134.asp
Date context
no registration or modification date could be verified for this entry in the IANA registry (blank in source; not fabricated); scan-activity observations reflect a live, rolling dashboard snapshot (accessed 2026-07-09), not a historical record [Confirmed] — https://isc.sans.edu/data/port/134; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
Analyst note
an open 134/udp is unlikely to indicate a live modern Ingres deployment given the documented port drift to the 21064–21071 range; treat as legacy/anomalous and investigate context before assuming Ingres-in-use.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
ingres-net UDP INGRES-NET Service 0.12%
ingres-net TCP INGRES-NET Service 0.00%
IANA name
ingres-net
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.