159
Summary
- // if you see it open
- No trojan/malware association found on the port lists checked (negative result, not proof of safety); no scan-exposure data available to gauge real-world open-port frequency.
- // analyst note
- A registry entry with no defining RFC and no modern usage evidence; treat an open 159/tcp as unusual and worth investigating rather than assuming legitimacy or malice.
About port 159/tcp.
Port 159/tcp is registered with IANA as nss-routing, described simply as "NSS-Routing," with both assignee and contact listed as [Yakov_Rekhter]; the same registration is dual-assigned to 159/udp with identical service name and description, and the Registration Date, Modification Date, Reference, Service Code, and Assignment Notes columns are all blank in the current registry — no RFC or other document is cited as backing the entry. The earliest documented appearance found is RFC 1340 (Internet Assigned Numbers, July 1992), which lists the same service-name/port pairing without further protocol detail; no later RFC, Internet-Draft, or vendor specification was located that actually defines what NSS-Routing does on the wire. The name invites an assumption of a link to Novell's NetWare Storage Services (NSS), but that connection could not be substantiated against Novell's own NSS/NLSP documentation and is flagged here as unverified rather than asserted as fact. No evidence of active, currently maintained software implementing this service was found, no port-specific scan/exposure telemetry (Shodan/Censys-style) was located, and the port does not appear on any of the trojan/malware port lists checked — a negative result that rules out known bad associations without confirming the port is in any way commonly seen. In short, 159/tcp is a decades-old, thinly documented IANA reservation that appears dormant in modern practice.
- IANA assignment
nss-routing— "NSS-Routing"; reference (blank — no RFC cited in IANA registry); assignee/contact [Yakov_Rekhter]; dual-registered 159/tcp + 159/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence
- Unknown — no port-specific Shodan/Censys/internet-wide-scan statistics located [Unknown]
- Related ports
- none identified as a notable cluster for this entry
Primary use
Unknown — no RFC or vendor spec defines the actual on-the-wire protocol; the registry only supplies the name/description
Other/unofficial uses
possible tie to Novell NetWare Storage Services (NSS) suggested by the name, but this could NOT be confirmed against Novell's own NSS/NLSP documentation — unverified
Security implications
no trojan/malware association found on the port lists checked (TrendMicro, Gary Kessler's bad-ports list, awesome-lists suspicious-ports CSV) — a negative result, not a safety confirmation
Typically seen on
Unknown — no evidence of current active deployments found; appears to be a legacy/dormant registration
- Earliest documentation
- RFC 1340 (Internet Assigned Numbers, July 1992) lists the same service-name/port pairing; true registration may predate this but is Unknown [Likely] — https://www.ietf.org/rfc/rfc1340.txt
- Analyst note
- A registry entry with no defining RFC and no modern usage evidence; treat an open 159/tcp as unusual and worth investigating rather than assuming legitimacy or malice.
About port 159/udp.
Port 159 is registered with IANA — identically on both UDP and TCP — as nss-routing, described simply as "NSS-Routing," with Yakov Rekhter listed as both assignee and contact. The IANA registry entry is otherwise sparse: the registration date, modification date, and reference (RFC) fields are all blank, and IANA does not document what protocol or wire format nss-routing actually speaks. No RFC, internet-draft, or vendor specification could be located that expands on the name beyond IANA's own one-line label, and no commonly deployed software, daemon, or client is known to bind to 159/udp today. That absence of a public spec, combined with the port's near-zero observed usage, points to a name reserved decades ago (plausibly tied to early IETF-era routing/security work associated with Rekhter) that was never widely implemented or was superseded before seeing production deployment. nmap's service-frequency data shows 159/udp responding in roughly 0.03% of scanned hosts and 159/tcp in effectively none, meaning a live listener on this port is unusual enough to be worth a second look rather than dismissed as routine background noise. No CVEs, malware families, or exploitation reports specific to 159/udp turned up in this pass, though that reflects the absence of public documentation for the service rather than a confirmed clean bill of health — an analyst encountering a live 159/udp responder should treat it as an unidentified or custom service until proven otherwise, not assume it maps neatly to the "NSS-Routing" label.
- IANA assignment
nss-routing— "NSS-Routing"; reference (blank — no RFC cited in IANA registry); assignee/contact [Yakov_Rekhter]; dual-registered 159/tcp + 159/udp with identical entries [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (rows 395–396); cross-checked https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt- Range class
- well-known (0–1023) [Confirmed]
- Registration/modification date
- blank in the IANA registry — left Unknown, not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (row 396)
- Prevalence
- nmap-services open-frequency 159/udp ≈ 0.000329 (~0.03%), 159/tcp ≈ 0.000000 (near-zero), consistent with a dormant/legacy registration [Likely] — https://svn.nmap.org/nmap/nmap-services
- Related ports
- 159/tcp (identical dual registration: nss-routing / NSS-Routing / Yakov_Rekhter) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (row 395)
Primary use / protocol semantics
no RFC or public spec found defining nss-routing's wire protocol or purpose beyond the short IANA label [Unknown]
Common software
no known or commonly deployed implementation identified in this pass [Unknown]
Security implications
no CVEs, malware, or exposure reporting specific to 159/udp found; near-zero prevalence means a live responder is atypical and warrants treatment as an unidentified/custom service rather than assumed legitimate nss-routing traffic
Typically seen on
no known typical deployment identified — appears largely unused/legacy [Unknown]
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| nss-routing | UDP | — | 0.03% |
| nss-routing | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.