154
Summary
- // if you see it open
- No CVE, NVD entry, or documented exploitation found. A low-authority aggregator (AuditMyPC) carries generic templated Trojan/Virus boilerplate repeated across many of its port pages, not a specific dated finding — not treated as a verified security fact.
- // analyst note
- dormant, sparsely documented legacy registration; an open port 154 in the wild would warrant investigation rather than be assumed benign or malicious by default, given the absence of both legitimate-use and threat documentation.
About port 154/tcp.
Port 154/tcp is registered with IANA under the service name netsc-prod, described only as "NETSC," with a blank Reference/RFC field and blank Assignee and Contact columns. The cached registry file carries two identical rows for this service name — one for tcp, one for udp — confirming the dual-registration pattern common to early IANA well-known-port entries; both rows share the same terse description and both leave Registration Date and Modification Date blank, which is recorded here as a sourced null rather than an inferred or fabricated date. Beyond the bare label, IANA's registry does not document what NETSC actually is or which vendor implemented it, and no RFC or reference document is cited for the assignment. A single web source raises, without being able to substantiate, a plausible legacy association: "netsc-prod" paired with the adjacent port 155's "netsc-dev" suggests a production/development pair for some 1980s-era network-services daemon, possibly tied to HP/HP3000 MPE-iX systems, but this could not be confirmed against a citable primary source and is reported here as unverified speculation, not fact. No CVE, vulnerability database entry, Shodan/Censys exposure data, or nmap-services prevalence figure was found for port 154. A low-authority aggregator (AuditMyPC) carries generic templated "a Trojan or Virus has used this port" boilerplate that recurs across many of its port pages and is not treated as a specific, dated security finding. Net assessment: this is a dormant, largely undocumented legacy IANA registration with no evidence of meaningful contemporary use, malicious or otherwise.
- IANA assignment
netsc-prod— "NETSC"; reference/RFC blank; assignee and contact blank; dual-registered 154/tcp + 154/udp with identical name/description [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (lines 385–386); cross-confirmed at https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml- Range class
- well-known (0–1023) [Confirmed]
- Registration/modification date
- blank in the cached IANA registry row; not fabricated or inferred [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Prevalence
- no nmap-services or internet-scan frequency data found for this port [Unknown]
- Related ports
- 155/tcp (
netsc-dev) — adjacent registration sharing the same naming convention [Likely, single-source] — https://www.speedguide.net/port.php?port=154
Primary use
Unknown / undocumented beyond the terse label "NETSC"
Other/unofficial uses
possible legacy HP/HP3000 MPE-iX network-services pairing with port 155 (netsc-dev), inferred from the naming pattern only; could not be corroborated by a citable primary source
Security implications
no CVE, NVD, or documented exploitation found; a generic templated "Trojan/Virus" warning appears on a low-authority aggregator across many of its port pages and is not a specific, dated security finding
Typically seen on
Unknown — no confirmed host/vendor association
- Analyst note
- dormant, sparsely documented legacy registration; an open port 154 in the wild would warrant investigation rather than be assumed benign or malicious by default, given the absence of both legitimate-use and threat documentation.
About port 154/udp.
Port 154/udp is registered with IANA as netsc-prod, described simply as "NETSC," with no listed assignee, no reference RFC, and no assignment or modification dates in the registry — this is a genuine dual TCP/UDP registration, since 154/tcp carries an identical service name and description. IANA's registry does not expand on what "NETSC" stood for or document any protocol specification, and no RFC was ever published for it. The strongest available context comes indirectly: ports 154 and 155 form a paired "prod"/"dev" set, and the sibling port 155/tcp+udp ("netsc-dev") is assigned in the IANA registry to Sergio Heker, who built and directed JvNCnet — the John von Neumann National Supercomputer Center's NSFNET regional network — beginning in 1985. That makes it reasonably likely, though not IANA-confirmed, that 154 and 155 were reserved together as internal JvNCnet network-management ports during the mid-to-late-1980s NSFNET era; no assignment date should be inferred from this, since the registry carries none for port 154 itself. No current software, daemon, or vendor product documents active use of UDP 154 today, and a consumer trojan/malware port-lookup database returns no known malicious association for it. One vendor threat-signature page nominally labeled "NETSC-PROD" cites the port-154 registration in its metadata but actually fingerprints unrelated traffic on entirely different ports (UDP 5246–5247, UDP/TCP 3386, UDP 3544, TCP 434) — mislabeled vendor boilerplate, not evidence of real 154/udp activity. For an analyst, UDP 154 reads as a dormant legacy registry entry: essentially never seen open in the wild, with no meaningful exposure or scanning relevance today.
- IANA assignment
netsc-prod— "NETSC"; reference (blank — no RFC cited in IANA registry); no assignee listed; dual-registered 154/tcp + 154/udp (identical name/description on both rows) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (154/udp), :385 (154/tcp); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services observed open-frequency 154/udp ≈ 0.000379 — very low (roughly 4 in 10,000 scanned hosts in the nmap-services sample); the paired 154/tcp row carries a frequency of 0 (never observed open in the same sample), so what little activity exists on this port number sits on the UDP side[Confirmed] — nmap-services dataset
- Related ports
- 155/tcp+udp (netsc-dev, sibling "dev" port, same historical-assignee context) [Confirmed] — IANA registry
Primary use
NETSC "production" port, paired with 155/tcp+udp ("netsc-dev"); IANA gives no expanded description or protocol spec beyond the short name
Security implications
no known malicious/trojan association in a consumer port-lookup database; a Juniper signature nominally named "NETSC-PROD" cites the port-154 registration but actually fingerprints unrelated traffic on different ports (UDP 5246–5247, UDP/TCP 3386, UDP 3544, TCP 434) — mislabeled vendor metadata, not evidence of real 154/udp activity; low exposure/scanning relevance overall
Typically seen on
none identified — no current software, daemon, or vendor product documents active use of UDP 154; effectively a dormant legacy registry entry [Unknown]
- Historical origin
- likely reserved as an internal JvNCnet (NSFNET regional network) management port in the mid-to-late-1980s, inferred from sibling port 155's assignee Sergio Heker (JvNCnet director from 1985) — not an IANA-stamped fact, no date in the registry for port 154[Likely] — https://www.connected.app/bg/ports/155; https://www.glesec.com/about-sergio/
- Analyst note
- UDP 154 is a dormant, undocumented legacy registration with no modern implementation or malware association found; treat an open 154/udp as an anomaly worth investigating rather than a normal service.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| netsc-prod | UDP | — | 0.04% |
| netsc-prod | TCP | NETSC | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.