Network port detail · UDP/TCP

154

Netsc-prod
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No CVE, NVD entry, or documented exploitation found. A low-authority aggregator (AuditMyPC) carries generic templated Trojan/Virus boilerplate repeated across many of its port pages, not a specific dated finding — not treated as a verified security fact.
// analyst note
dormant, sparsely documented legacy registration; an open port 154 in the wild would warrant investigation rather than be assumed benign or malicious by default, given the absence of both legitimate-use and threat documentation.
[ 01 ] — Context

About port 154/tcp.

Updated  ·  Confidence: Low

Port 154/tcp is registered with IANA under the service name netsc-prod, described only as "NETSC," with a blank Reference/RFC field and blank Assignee and Contact columns. The cached registry file carries two identical rows for this service name — one for tcp, one for udp — confirming the dual-registration pattern common to early IANA well-known-port entries; both rows share the same terse description and both leave Registration Date and Modification Date blank, which is recorded here as a sourced null rather than an inferred or fabricated date. Beyond the bare label, IANA's registry does not document what NETSC actually is or which vendor implemented it, and no RFC or reference document is cited for the assignment. A single web source raises, without being able to substantiate, a plausible legacy association: "netsc-prod" paired with the adjacent port 155's "netsc-dev" suggests a production/development pair for some 1980s-era network-services daemon, possibly tied to HP/HP3000 MPE-iX systems, but this could not be confirmed against a citable primary source and is reported here as unverified speculation, not fact. No CVE, vulnerability database entry, Shodan/Censys exposure data, or nmap-services prevalence figure was found for port 154. A low-authority aggregator (AuditMyPC) carries generic templated "a Trojan or Virus has used this port" boilerplate that recurs across many of its port pages and is not treated as a specific, dated security finding. Net assessment: this is a dormant, largely undocumented legacy IANA registration with no evidence of meaningful contemporary use, malicious or otherwise.

IANA assignment
netsc-prod — "NETSC"; reference/RFC blank; assignee and contact blank; dual-registered 154/tcp + 154/udp with identical name/description [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (lines 385–386); cross-confirmed at https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Range class
well-known (0–1023) [Confirmed]
Registration/modification date
blank in the cached IANA registry row; not fabricated or inferred [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Prevalence
no nmap-services or internet-scan frequency data found for this port [Unknown]
Related ports
155/tcp (netsc-dev) — adjacent registration sharing the same naming convention [Likely, single-source] — https://www.speedguide.net/port.php?port=154

Primary use

Unknown / undocumented beyond the terse label "NETSC"

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Other/unofficial uses

possible legacy HP/HP3000 MPE-iX network-services pairing with port 155 (netsc-dev), inferred from the naming pattern only; could not be corroborated by a citable primary source

[Unknown/single-source] — https://www.speedguide.net/port.php?port=154

Security implications

no CVE, NVD, or documented exploitation found; a generic templated "Trojan/Virus" warning appears on a low-authority aggregator across many of its port pages and is not a specific, dated security finding

[Likely, discounted] — https://www.auditmypc.com/tcp-port-154.asp

Typically seen on

Unknown — no confirmed host/vendor association

Analyst note
dormant, sparsely documented legacy registration; an open port 154 in the wild would warrant investigation rather than be assumed benign or malicious by default, given the absence of both legitimate-use and threat documentation.
[ 02 ] — Context

About port 154/udp.

Updated  ·  Confidence: Medium

Port 154/udp is registered with IANA as netsc-prod, described simply as "NETSC," with no listed assignee, no reference RFC, and no assignment or modification dates in the registry — this is a genuine dual TCP/UDP registration, since 154/tcp carries an identical service name and description. IANA's registry does not expand on what "NETSC" stood for or document any protocol specification, and no RFC was ever published for it. The strongest available context comes indirectly: ports 154 and 155 form a paired "prod"/"dev" set, and the sibling port 155/tcp+udp ("netsc-dev") is assigned in the IANA registry to Sergio Heker, who built and directed JvNCnet — the John von Neumann National Supercomputer Center's NSFNET regional network — beginning in 1985. That makes it reasonably likely, though not IANA-confirmed, that 154 and 155 were reserved together as internal JvNCnet network-management ports during the mid-to-late-1980s NSFNET era; no assignment date should be inferred from this, since the registry carries none for port 154 itself. No current software, daemon, or vendor product documents active use of UDP 154 today, and a consumer trojan/malware port-lookup database returns no known malicious association for it. One vendor threat-signature page nominally labeled "NETSC-PROD" cites the port-154 registration in its metadata but actually fingerprints unrelated traffic on entirely different ports (UDP 5246–5247, UDP/TCP 3386, UDP 3544, TCP 434) — mislabeled vendor boilerplate, not evidence of real 154/udp activity. For an analyst, UDP 154 reads as a dormant legacy registry entry: essentially never seen open in the wild, with no meaningful exposure or scanning relevance today.

IANA assignment
netsc-prod — "NETSC"; reference (blank — no RFC cited in IANA registry); no assignee listed; dual-registered 154/tcp + 154/udp (identical name/description on both rows) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (154/udp), :385 (154/tcp); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services observed open-frequency 154/udp ≈ 0.000379 — very low (roughly 4 in 10,000 scanned hosts in the nmap-services sample); the paired 154/tcp row carries a frequency of 0 (never observed open in the same sample), so what little activity exists on this port number sits on the UDP side
[Confirmed] — nmap-services dataset
Related ports
155/tcp+udp (netsc-dev, sibling "dev" port, same historical-assignee context) [Confirmed] — IANA registry

Primary use

NETSC "production" port, paired with 155/tcp+udp ("netsc-dev"); IANA gives no expanded description or protocol spec beyond the short name

[Confirmed] — IANA Service Name and Transport Protocol Port Number Registry

Security implications

no known malicious/trojan association in a consumer port-lookup database; a Juniper signature nominally named "NETSC-PROD" cites the port-154 registration but actually fingerprints unrelated traffic on different ports (UDP 5246–5247, UDP/TCP 3386, UDP 3544, TCP 434) — mislabeled vendor metadata, not evidence of real 154/udp activity; low exposure/scanning relevance overall

[Likely] — https://www.grc.com/port_154.htm; https://www.juniper.net/us/en/threatlabs/application-signatures/detail.NETSC-PROD.html

Typically seen on

none identified — no current software, daemon, or vendor product documents active use of UDP 154; effectively a dormant legacy registry entry [Unknown]

Historical origin
likely reserved as an internal JvNCnet (NSFNET regional network) management port in the mid-to-late-1980s, inferred from sibling port 155's assignee Sergio Heker (JvNCnet director from 1985) — not an IANA-stamped fact, no date in the registry for port 154
[Likely] — https://www.connected.app/bg/ports/155; https://www.glesec.com/about-sergio/
Analyst note
UDP 154 is a dormant, undocumented legacy registration with no modern implementation or malware association found; treat an open 154/udp as an anomaly worth investigating rather than a normal service.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
netsc-prod UDP 0.04%
netsc-prod TCP NETSC 0.00%
IANA name
netsc-prod
Transport
TCP (ALSO REGISTERED IDENTICALLY ON UDP)
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.