145
Summary
- // if you see it open
- No CVEs or malware/backdoor associations found for this port in this research pass; not on standard commonly-scanned/attacked port lists. Absence of evidence is not evidence of absence — treat a live listener as unusual and worth investigating.
- // analyst note
- a rarely-observed, registry-only assignment; treat any live listener on 145/tcp as unusual and worth investigating rather than routine.
About port 145/tcp.
Port 145/tcp is registered with IANA under the service name uaac, with the description "UAAC Protocol" and assignee David A. Gomberg. The IANA Reference column is blank — no RFC or other specification document is cited for this assignment, so no protocol definition can be linked or summarized. The registration is dual-listed on both TCP and UDP: 145/udp carries an identical service name, description, and assignee, with no divergence between the two rows in the IANA registry. Beyond the bare registry entry, no authoritative or corroborating source could be located describing what "UAAC" stands for, what software (if any) has ever implemented it, or how the assignment has been used in practice. A gloss of "User Access Authorization Control" circulates on secondary port-list aggregator sites, but it traces to no IANA publication or spec and is not treated as confirmed here. No scan-statistics dataset, CVE, or malware association naming port 145 was found, and it does not appear on standard lists of commonly probed or attacked ports. Overall, this entry is best treated as a registered-but-essentially-undocumented assignment: the registry facts are solid, everything about real-world usage is unverified.
- IANA assignment
uaac— "UAAC Protocol"; reference blank (no RFC cited); assignee David A. Gomberg; dual-registered 145/tcp + 145/udp with identical service name/description/assignee on both rows [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt (cross-checked against the cached the IANA Service Name and Transport Protocol Port Number Registry, lines 367-368)- Range class
- well-known (0–1023) [Confirmed] — port number range is a structural fact of the IANA registry
- Prevalence / exposure
- Unknown — no scan-statistics dataset or exposure study covering port 145 specifically was located; it is not on standard commonly-scanned/attacked port lists (contrast with 21/22/23/135/445/3389) [Unknown]
Protocol name expansion
the "User Access Authorization Control" gloss seen on secondary port-list sites is unsourced and not an IANA-published expansion; no spec or RFC backs it [Unknown]
Primary use / protocol behavior
Unknown — no RFC, spec, or protocol document exists for this assignment [Unknown]
Common software
no verifiable current or historical software/daemon found that implements or listens on port 145; secondary aggregators (SpeedGuide, AuditMyPC, adminsub.net) only mirror the bare registry entry, and Cisco NBAR's "UAAC" protocol-pack label likewise reflects registry mirroring, not evidence of deployment [Unknown] — https://www.speedguide.net/port.php?port=145, https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/qos_nbar/prot_lib/config_library/pp900/nbar-prot-pack900/nbar-prot-uv900.pdf
Security implications
Unknown — no CVEs or malware/backdoor associations found tied to this port in this research pass; absence of evidence is not evidence of absence, so an observed listener should still be investigated rather than assumed benign [Unknown]
Typically seen on
Unknown — no deployment pattern could be established
- Analyst note
- a rarely-observed, registry-only assignment; treat any live listener on 145/tcp as unusual and worth investigating rather than routine.
About port 145/udp.
Port 145/udp is registered with IANA under the service name uaac, described simply as "UAAC Protocol," with assignee David A. Gomberg and no reference (RFC) field populated — a status confirmed by both the cached registry CSV and IANA's live service-names-port-numbers text file, and dual-registered identically on the TCP sibling (145/tcp), which carries the same service name, description, and assignee, with every other registry column (Registration Date, Modification Date, Reference, Service Code, Unauthorized Use Reported, Assignment Notes) left blank in both rows. Despite the registration's longevity, no public specification, RFC, or documented protocol behavior for UAAC has ever surfaced — a 2002 seclists.org mailing-list thread shows security researchers investigating the port and coming up empty-handed, which is itself the best evidence available that "UAAC Protocol" is a name-only registration with no known real-world implementation. No vendor or open-source daemon under that name was found; a FreeBSD mailing-list reference indicates the port appears only as an inert /etc/services stub, not an active service. The one concrete security event tied to port 145 at all is the 2002 "XC telnetd worm," which installed a rootshell backdoor via TCP port 145 on BSD-based telnetd hosts — but that incident is specific to the TCP transport and must not be conflated with 145/udp, for which no dedicated incident or scanning data was found. Port 145 is also entirely absent from Wikipedia's port list (the table jumps from 143 to 151), consistent with the entry's overall obscurity. For an analyst, a live response on 145/udp today has no documented legitimate use and should be treated as anomalous rather than assumed benign.
- IANA assignment
uaac— "UAAC Protocol"; reference (blank — no RFC cited in IANA registry); assignee David A. Gomberg; dual-registered 145/tcp + 145/udp with identical, otherwise-blank rows [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (row 367 = tcp counterpart); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt- Range class
- well-known (0–1023)
- Prevalence
- nmap-services observed open-frequency 145/udp ≈ 0.001153 — very low (roughly 1 in 1,000 sampled hosts), 316th of 5,615 UDP entries; the TCP sibling 145/tcp records 0. The figure measures how often the port answers a scan, not UAAC use — nothing identifies what is listening[Likely] — nmap-services dataset
- Related ports
- 145/tcp (identical dual registration, same service name/description/assignee) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Primary use
Unknown — no RFC, specification, or documented protocol behavior for UAAC has ever been published; a 2002 researcher thread investigating the port found nothing
Other/unofficial uses
none identified — no vendor or open-source software implementing "UAAC" was found; FreeBSD's /etc/services carries only the inert IANA stub
Security implications
no incident specific to 145/udp was found. The 2002 "XC telnetd worm" installed a rootshell backdoor via TCP port 145 on BSD-based telnetd hosts — specific to 145/tcp, not this UDP entry
Typically seen on
no current (2026) exposure telemetry specific to 145/udp was found beyond the nmap-services open-frequency figure above; real-world exposure is presumed negligible but no source identifies a host class [Unknown]
- Analyst note
- a live response on 145/udp has no documented legitimate purpose today; investigate as anomalous rather than assume benign, and do not conflate with the TCP-145 telnetd-worm history.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| uaac | UDP | UAAC Protocol | 0.12% |
| uaac | TCP | UAAC Protocol | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.