157
Summary
- // if you see it open
- No known CVEs or malware associations tied to knet-cmp/157. Given the vestigial mainframe-era origin and no known modern implementations, an unexpected open 157/tcp is more likely a misconfigured/custom service or scanning artifact than genuine KNET/VM traffic — fingerprint rather than trust the port number.
- // analyst note
- treat an open 157/tcp as anomalous rather than trust the port number; fingerprint the actual listening service.
About port 157/tcp.
Port 157/tcp is registered with IANA as knet-cmp, described as "KNET/VM Command/Message Protocol," assignee Gary S. Malkin, with a blank Reference field. The registration is dual — 157/udp carries the identical service name, description, and assignee — which is typical of the mid-to-late-1980s well-known-port block this entry sits in. Several third-party legacy port listings (t1shopper, auditmypc, speedguide, and similar mirrors) attach RFC 1340 ("Assigned Numbers," October 1992) to this entry, but RFC 1340 is a whole-registry snapshot document that lists hundreds of ports side by side, not a protocol specification for KNET/VM specifically, so it is deliberately not recorded here as the IANA Reference — the field stays blank, matching the live registry. No authoritative technical description of the KNET/VM wire protocol, no implementing software, and no CVE or malware data specific to port 157 could be located in this pass; scan prevalence is measurable but negligible — the nmap-services dataset records an observed open-frequency of about 0.000113 for 157/tcp, roughly 1 in 10,000 scanned hosts, with 157/udp at about 0.000247; "KNET/VM" appears to be an obscure IBM VM/CMS mainframe-era command/message facility, distinct from IBM's separately documented VNET networking product, and should not be assumed related to it. Given the vestigial 1980s mainframe origin and the complete absence of modern deployment evidence, an unexpected open 157/tcp today should be treated as an anomaly to be fingerprinted rather than assumed to be legitimate knet-cmp traffic — similar in character to the neighboring legacy registrations at 156/tcp (sqlsrv) and 158/tcp (pcmail-srv) already enriched in this project.
- IANA assignment
knet-cmp— "KNET/VM Command/Message Protocol"; reference (blank — no RFC cited in IANA registry); assignee Gary S. Malkin; dual-registered 157/tcp + 157/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services observed open-frequency 157/tcp ≈ 0.000113 (very low — roughly 1 in 10,000 scanned hosts in the nmap-services sample); the dual-registered 157/udp side is somewhat higher at ≈ 0.000247 [Confirmed] — nmap-services dataset. The figure records scan-observed openness on the port number, not confirmed KNET/VM use, and is consistent with comparably obscure 1980s registrations in this range (156/tcp sqlsrv, 158/tcp pcmail-srv) being rare-to-nonexistent in modern scans[Likely] — contextual comparison
- Related ports
- 156/tcp (sqlsrv), 158/tcp (pcmail-srv) — adjacent largely-vestigial 1980s well-known registrations already enriched in this project; 157/udp is the dual-registered sibling [Confirmed] — IANA registry
Primary use
registered IANA service name for the KNET/VM Command/Message Protocol; no identifiable modern deployment
Other/unofficial uses
Unknown — no vendor documentation, protocol description, or implementing software identified [Unknown]
Security implications
no known CVEs or malware associated with knet-cmp/157; because the registration is a vestigial mainframe-era protocol with no known modern install base, an open 157/tcp is more plausibly a misconfiguration, custom service, or scanning artifact than genuine KNET/VM traffic
Typically seen on
Unknown — no evidence of any current host type running this service
- Analyst note
- treat an open 157/tcp as anomalous rather than trust the port number; fingerprint the actual listening service.
About port 157/udp.
Port 157/udp is registered with IANA as knet-cmp, described as the "KNET/VM Command/Message Protocol," with assignee and contact both listed as Gary S. Malkin. The entry is dual-registered — an identical row exists for 157/tcp — and carries no RFC or reference document; the Reference, Registration Date, and Modification Date fields are all blank in the registry, a gap that is faithfully preserved here rather than filled with an invented date. KNET was a protocol associated with IBM mainframe VM/CMS environments, placing this assignment in the BITNET/EARN academic-networking era of the IANA registry — a period, along with the "cmp" (command/message protocol) naming, that predates the modern commodity Internet and reflects assignments made when the registry served a much smaller, more institutional set of network operators. No current mainstream client, server, or daemon implementing knet-cmp could be identified in this research pass; secondary port-listing mirrors reproduce only the bare IANA entry without additional attribution. No CVEs, malware associations, or exposure-scanning statistics specific to this port were found, and general UDP-scanning literature notes only that UDP services are inherently harder to enumerate than TCP — a generic property, not a finding specific to 157/udp. The overall picture is a legacy, effectively dormant registry entry with no evidence of contemporary real-world deployment.
- IANA assignment
knet-cmp— "KNET/VM Command/Message Protocol"; assignee/contact Gary S. Malkin ([Gary_S_Malkin]); Reference field blank; dual-registered 157/tcp + 157/udp [Confirmed, two angles — cached registry row and live fetch agree] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt- Registration Date / Modification Date
- blank in the IANA source; left null, not fabricated [Confirmed, two angles agree the fields are blank] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- IANA reference/RFC
- none listed; left blank per no-fabrication rule (no RFC exists for this entry) [Confirmed, two angles agree] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- Range class
- well-known (0–1023)
- Related ports
- none specific identified beyond its own TCP/UDP dual registration (157/tcp) [Unknown]
Primary use
historical KNET (VM/CMS command/message) protocol from the BITNET/EARN-era mainframe networking world; decades-old, Gary Malkin-era registry assignment with no evidence of modern active use
Common software
no current mainstream implementation identified; only secondary port-listing mirrors (e.g. SpeedGuide) reproduce the bare registry entry
Security implications / exposure scanning
no CVEs, malware associations, or Shodan/Censys/SANS ISC scanning statistics specific to 157/udp were found; general UDP-scan literature notes UDP is harder to enumerate than TCP, but that is not specific to this port
Typically seen on
no confirmed modern deployment; historically would map to legacy IBM VM/CMS / BITNET-EARN mainframe hosts based on the protocol name, but this is an inference from the registry description rather than an observed deployment
- Analyst note
- legacy, low-visibility registry entry with no documented contemporary usage, CVEs, or scanning trend as of this research pass (2026-07-10); treat an open 157/udp as unusual and worth investigating rather than expected.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| knet-cmp | UDP | KNET/VM Command/Message Protocol | 0.02% |
| knet-cmp | TCP | KNET/VM Command/Message Protocol | 0.01% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.