Network port detail · UDP/TCP

150

Sql-net
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Not flagged as trojan/virus-associated on Gary Kessler's Bad Ports list, the Chebucto Trojan TCP/IP Ports table, or AuditMyPC (explicit 'No'). No established typical use pattern; an unexpected live 150/tcp listener warrants investigation rather than assumption of database service.
// analyst note
a secondary source (connected.app) frames port 150 as "Oracle's abandoned front door" paired historically with port 66; this is uncorroborated by the primary IANA record, which shows two distinct registrants for the two ports — flagged Likely/uncorroborated, not adopted as fact [Likely] — https://www.connected.app/ports/150
[ 01 ] — Context

About port 150/tcp.

Updated  ·  Confidence: Medium

Port 150/tcp is registered with IANA under the service name sql-net, description "SQL-NET," with assignee and contact both listed as [Martin_Picard]. The Registration Date, Modification Date, and Reference (RFC) columns are all blank in the registry — this is a legacy assignment from IANA's early port-registration era, before those metadata fields were consistently populated, not a data gap on our end. The entry is dual-registered: 150/udp carries an identical service name and description under the same assignee, with all other fields equally blank. A natural but incorrect inference is that this is "the" Oracle SQL*Net port, given the name — however, the raw registry shows a separate, differently-assigned entry at port 66 ("Oracle SQL*NET," assignee Jack_Haverty), which is a distinct registration from Martin_Picard's generic "SQL-NET" at port 150. In practice, real-world Oracle Net (SQL*Net/Net8) traffic runs on port 1521 by convention, not port 150 or 66. No mainstream database client or server is currently documented as defaulting to port 150. Multiple malicious-port reference lists (Gary Kessler's Bad Ports, the Chebucto trojan-port table, and AuditMyPC's port-150 page) do not flag it as trojan- or virus-associated; AuditMyPC's page explicitly answers "No" to that question. A secondary-source claim describing port 150 as "Oracle's abandoned front door" tied to port 66 is not corroborated by the primary IANA record and is treated as unverified.

IANA assignment
sql-net — "SQL-NET"; assignee/contact [Martin_Picard]; Registration Date, Modification Date, and Reference blank in registry; dual-registered 150/tcp + 150/udp (identical entries) [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt (cross-checked against local registry CSV, source-file citation: the IANA Service Name and Transport Protocol Port Number Registry, lines 377–378)
Range class
well-known (0–1023) [Confirmed]
Prevalence
the nmap-services dataset records sql-net on 150/tcp with an open-frequency of 0.000013 — the dataset's lowest nonzero step, shared by roughly two hundred other service rows, i.e. about a hundredth of one percent of sampled hosts; the 150/udp sibling is markedly higher at 0.00084
[Confirmed] — nmap-services dataset
Related ports
port 66 (separate, differently-registered "Oracle SQL*NET" entry — do not conflate); port 1521 (conventional real-world Oracle Net port) [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt

Primary use

generic legacy "SQL-NET" service registration; commonly but not authoritatively associated with Oracle-family database networking by name similarity — the IANA description itself carries no Oracle attribution, and the distinct port-66 "Oracle SQL*NET" registration (assignee Jack_Haverty) is a separate entry, not the same assignment [Likely] — https://www.chebucto.ns.ca/~rakerman/oracle-port-table.html, https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt

Other/unofficial uses

no mainstream software currently documented as defaulting to this port; real Oracle Net (SQL*Net/Net8) traffic conventionally runs on port 1521, not 150 [Unknown/Likely]

Security implications

not listed on Gary Kessler's Bad Ports list, the Chebucto Trojan TCP/IP Ports table, or flagged by AuditMyPC (explicit "No" for virus/trojan) [Confirmed] — https://www.garykessler.net/library/bad_ports.html, http://www.chebucto.ns.ca/~rakerman/trojan-port-table.html, https://www.auditmypc.com/tcp-port-150.asp

Typically seen on

no established typical deployment pattern found; treat any live 150/tcp listener as unusual and investigate rather than assume database service [Unknown]

Analyst note
a secondary source (connected.app) frames port 150 as "Oracle's abandoned front door" paired historically with port 66; this is uncorroborated by the primary IANA record, which shows two distinct registrants for the two ports — flagged Likely/uncorroborated, not adopted as fact
[Likely] — https://www.connected.app/ports/150
[ 02 ] — Context

About port 150/udp.

Updated  ·  Confidence: Medium

Port 150/udp is registered with IANA under the service name sql-net, description "SQL-NET," with both the assignee and contact fields listing Martin Picard. The Registration Date, Modification Date, Reference (RFC/IANA), Service Code, Unauthorized Use Reported, and Assignment Notes columns are all blank in the live IANA registry — nothing was fabricated to fill those gaps. The entry is dual-registered: an identical row exists at 150/tcp with the same service name, description, and assignee/contact. Despite the "SQL-NET" name inviting comparison to Oracle's networking stack, the IANA description carries no Oracle attribution, and a distinct, separately assigned "Oracle SQL*NET" registration exists at port 66 under a different assignee (Jack Haverty) — the two entries should not be conflated. Real-world Oracle Net (SQL*Net/Net8) traffic conventionally runs on TCP 1521, not port 150, and no mainstream database client or server is documented as defaulting to UDP 150 today. A direct fetch of AuditMyPC's UDP-150 page returns "Virus/Trojan: No," and the port carries no separate listing on Gary Kessler's Bad Ports list or the Chebucto Trojan Ports table. No nmap-services scan-frequency figure for udp/150 was located, so prevalence is left Unknown rather than guessed. Given the absence of any documented legitimate deployment, an unexpected live listener on 150/udp is worth investigating rather than assumed to be a database service.

IANA assignment
sql-net — "SQL-NET"; assignee/contact [Martin_Picard]; Reference field blank (no RFC cited); dual-registered 150/tcp + 150/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=150
Registration/modification dates
blank in the IANA registry — not recorded, not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=150
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services observed open-frequency 150/udp ≈ 0.00084 — very low (roughly 8 in 10,000 scanned hosts in the nmap-services sample); the paired 150/tcp row is far rarer at ≈ 0.000013, so essentially all observed activity on this port number sits on the UDP side [Confirmed] — nmap-services dataset
Related ports
150/tcp (identical dual registration, same assignee); 66 (separate "Oracle SQL*NET" registration, different assignee — do not conflate); 1521 (conventional real-world Oracle Net port) [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt

Primary use

generic legacy "SQL-NET" registration; not the same as the separately assigned "Oracle SQL*NET" entry at port 66 (assignee Jack Haverty); real-world Oracle Net conventionally runs on TCP 1521, not this port [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt; https://www.chebucto.ns.ca/~rakerman/oracle-port-table.html

Other/unofficial uses

none identified in this pass [Unknown]

Security implications

AuditMyPC's UDP-150 page reports Virus/Trojan: "No"; not listed on Gary Kessler's Bad Ports list or the Chebucto Trojan Ports table

[Confirmed] — https://www.auditmypc.com/udp-port-150.asp; https://www.garykessler.net/library/bad_ports.html

Typically seen on

no established deployment pattern found [Unknown]

Malware associations

none confirmed

[Confirmed] — https://www.auditmypc.com/udp-port-150.asp
Analyst note
a secondary, undated third-party source (connected.app) frames port 150 as historically Oracle-related and paired with port 66; this is not corroborated by the primary IANA record, which shows two distinct registrants — treated as uncorroborated color, not adopted as fact
[Likely] — https://www.connected.app/ports/150
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
sql-net UDP 0.08%
sql-net TCP 0.00%
IANA name
sql-net
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.