148
Summary
- // if you see it open
- No confirmed trojan/malware association. garykessler.net's Bad Ports list and Simovits-derived compilations do not name port 148. auditmypc.com's TCP-148 page returns 'Virus/Trojan: No'; that site's generic disclaimer text is boilerplate on all port pages, not port-148-specific evidence.
- // analyst note
- A responsive port 148 is rare and undocumented beyond the bare IANA name/description; treat as an unusual finding to investigate in context rather than a known service or known-bad indicator.
About port 148/tcp.
Port 148/tcp is registered with IANA under the service name jargon, description "Jargon," with Bill Weinman listed as both assignee and contact. The entry is dual-registered — an identical jargon row exists for 148/udp with the same name, description, and assignee — and the IANA Reference column is blank, meaning no RFC or other standards-track document is cited for this assignment; that blank is left as-is rather than backfilled with an invented RFC number. Beyond the bare registry listing, no protocol specification, whitepaper, or vendor documentation describing what the "jargon" service actually does could be located, so its primary function is genuinely Unknown rather than withheld. No current mainstream client, server, database, or appliance software was found to bind to or document port 148 in vendor port-reference guides. On the security side, dedicated bad-port and trojan-port references (garykessler.net's "Bad Ports" list, Simovits-derived compilations) do not name port 148, and while generic port-lookup aggregator sites carry boilerplate "Virus/Trojan" disclaimer text on every port page, auditmypc.com's own TCP-148 page explicitly returns "No" for that flag. Net assessment: port 148 shows no established malicious signature and appears to be a low-prevalence, largely unimplemented legacy IANA assignment from an individual-registrant era of the ports registry, so a live host answering on 148/tcp is unusual and worth investigating on its own context rather than treating as a known service or a known-bad indicator.
- IANA assignment
jargon— "Jargon"; reference (blank — no RFC cited in IANA registry); assignee/contact Bill Weinman; dual-registered 148/tcp + 148/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (service-names-port-numbers.txt)- Range class
- well-known (0–1023) [Confirmed] — IANA registry
- Prevalence
- nmap-services observed open-frequency 148/tcp ≈ 0.000013 — the dataset's lowest nonzero step [Confirmed] — nmap-services dataset; the 148/udp row (registered
cronusin nmap's own table,jargonat IANA) is ≈ 0.000445, some thirty-four times higher. Both negligible, corroborating the low-prevalence reading - Related ports
- none established from this pass
Primary use
Unknown — no protocol spec, RFC, or vendor documentation for the "jargon" service was found; likely an individual-registrant-era assignment with no widely implemented protocol behind it
Other/unofficial uses
none identified; no mainstream software documented as binding to port 148 [Unknown]
Security implications
no confirmed trojan/malware association; garykessler.net's Bad Ports list has no entry for 148; auditmypc.com's TCP-148 page returns "Virus/Trojan: No" (the generic disclaimer text on that site is boilerplate present on all its port pages, not port-148-specific evidence)
Typically seen on
not established; no vendor/software association found — an open port 148 is an anomaly worth investigating rather than a recognized service fingerprint
- Analyst note
- A responsive port 148 is rare and undocumented beyond the bare IANA name/description; treat as an unusual finding to investigate in context rather than a known service or known-bad indicator.
About port 148/udp.
Port 148/udp is registered with IANA under the service name jargon, with the description field reading simply "Jargon" and the assignee listed as Bill Weinman. The registry's Reference column is blank, so no RFC or Internet-Draft ties this assignment to a documented protocol, and the cached copy of the Service Names and Port Numbers registry (rows 373–374) shows no registration date, modification date, service code, or unauthorized-use notes for it either. The same service name, description, and assignee also cover 148/tcp, making this a standard dual TCP/UDP registration rather than a UDP-only allocation. Beyond the bare registry stub, no public protocol specification, vendor implementation, or widely used software could be found describing what a "Jargon" service on this port is meant to do — it reads as a name reservation rather than an active, documented protocol. Independent web research corroborates the IANA stub but adds nothing substantive: several consumer port-lookup sites display generic "malware/trojan" warning boilerplate for port 148, but the same templated language recurs across many unrelated ports on those sites with no CVE, malware family, or dated incident cited, so it is treated as unverifiable rather than a genuine security finding. Analysts encountering traffic on 148/udp should treat it primarily as a dormant/reserved IANA allocation; live traffic here is more likely a local convention, misconfiguration, or unrelated ephemeral use than the "Jargon" service the name implies.
- IANA assignment
jargon— "Jargon"; reference blank; assignee Bill Weinman; dual-registered 148/tcp + 148/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt); cached the IANA Service Name and Transport Protocol Port Number Registry rows 373-374- Range class
- well-known (0–1023) [Confirmed]
- Registration/modification dates
- blank in both the live IANA registry and the cached CSV — left blank, not fabricated [Confirmed] — same source as above
- Prevalence
- nmap-services observed open-frequency 148/udp ≈ 0.000445 (very low — roughly 4 in 10,000 scanned hosts in the nmap-services sample) [Confirmed] — nmap-services dataset; the dual-registered 148/tcp side is rarer still at ≈ 0.000013 [Confirmed] — nmap-services dataset
- Related ports
- 148/tcp (identical dual IANA registration, same assignee/contact, same blank reference/date fields) [Confirmed] — same registry source
Primary use / protocol definition
Unknown — no RFC, spec, or known implementation found beyond the bare name reservation [Unknown]
Other/unofficial uses
Unknown — no known software found implementing a service under the "jargon" name [Unknown]
Security implications
Unknown/unverifiable — generic consumer port-lookup sites (auditmypc.com, speedguide.net, tcp-udp-ports.com) show templated malware/trojan flags for this port with no dated incident, malware family, or CVE cited, and the same boilerplate recurs across many unrelated ports on those sites; not treated as a genuine finding [Unknown]
Typically seen on
Unknown — no corroborated usage pattern found
- Analyst note
- Treat 148/udp as a dormant/reserved IANA stub rather than an active service; unexpected live traffic warrants investigation as anomalous rather than assumed "Jargon" protocol activity.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| cronus | UDP | CRONUS-SUPPORT | 0.04% |
| cronus | TCP | jargon | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.