16
Summary
- // if you see it open
- No malware family, named exploit, or CVE is attributed to port 16 in public threat-intelligence sources checked. Because the port is unassigned, any host answering on 16/tcp is running non-standard or undocumented software (custom application, misconfiguration, or unauthorized software), which can itself be a detection signal. No documented scanning campaign, malware, or backdoor targets it specifically; it is swept incidentally by broad opportunistic scanners and indexed by internet-wide scanning services.
- // analyst note
- There is no standardized service for port 16 — treat any open 16/tcp as non-standard software and investigate; do not assume a benign default.
About port 16/tcp.
Port 16/tcp is listed as Unassigned in the IANA Service Name and Transport Protocol Port Number Registry: the service-name column is empty, there is no assignee, no description beyond the "Unassigned" status, and the IANA Reference column is blank (no RFC). Both 16/tcp and 16/udp carry the same Unassigned status — the registry holds the number open on both transports rather than delegating it to any protocol. The absence is long-standing rather than a recent de-assignment: RFC 1700 (Assigned Numbers, J. Reynolds and J. Postel, October 1994) already showed port 16 with no well-known service, so it appears never to have held a registered designation. One disambiguation is worth recording because it recurs in third-party port lists: the Message Send Protocol (MSP, RFC 1159 / RFC 1312) is occasionally mis-cited against port 16, but MSP is assigned to port 18, not 16 — port 16 has no such association. For an analyst the practical consequence is that no legitimate, standardized service should answer on this port, so any host responding on 16/tcp is running non-standard or undocumented software, which is itself a detection signal in network monitoring. No specific malware family, named exploit, or CVE is attributed to port 16 in the public threat-intelligence sources checked, and no documented mass-scanning campaign targets it specifically — though, like all low-numbered ports, it is swept incidentally by broad opportunistic scanners and indexed by internet-wide scanning services. Because the port is unassigned, treat a responsive 16/tcp as a misconfiguration, a custom application, or a possible backdoor or decoy rather than a normal service.
- IANA assignment
- none — listed as Unassigned; service-name column empty, no assignee, reference field blank (no RFC cited); dual-registered Unassigned on 16/tcp + 16/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry lines 36–37)
- Range class
- well-known (0–1023)
- Prevalence
- Unknown — no per-port open-frequency figure recorded for 16/tcp in sources checked [Unknown]
- Related ports
- the small/legacy low-port cluster (7, 9, 11, 13, 17, 19) that surrounds it; adjacent Unassigned ports 14 and 15
Primary use
none — no IANA-assigned protocol; RFC 1700 (1994) also listed port 16 as unassigned, so it has no historical well-known service either
Other/unofficial uses
Unknown — no standard software is documented as legitimately binding to 16/tcp; note that Message Send Protocol (MSP) is sometimes wrongly cited for port 16 — MSP is assigned to port 18, not 16
Security implications
no malware family, named exploit, or CVE attributed to port 16 in public threat intel checked; because the port is unassigned, any host answering on it is running non-standard/undocumented software (custom app, misconfiguration, or unauthorized software) and may warrant investigation as a detection signal
Exposure / scanning
no documented scanning campaign, CVE, malware, or backdoor specifically targets 16/tcp; low-numbered unassigned ports are probed incidentally by broad opportunistic sweeps and indexed by internet-wide scanners; firewall rules generally do not single out port 16 [Likely]
Typically seen on
no expected legitimate listener; a responsive 16/tcp is an anomaly worth investigating
- Analyst note
- There is no standardized service for port 16 — treat any open 16/tcp as non-standard software and investigate; do not assume a benign default.
About port 16/udp.
Port 16/udp is listed as Unassigned in the IANA Service Name and Transport Protocol Port Number Registry: the service-name column is empty, there is no assignee, no description beyond the "Unassigned" status, and the IANA Reference column is blank (no RFC). Both 16/udp and 16/tcp carry the same Unassigned status — the registry holds the number open on both transports rather than delegating it to any protocol. The slot is raw, with no historical annotation: unlike the neighbouring port 15, whose TCP row carries the bracket note "Unassigned [was netstat]," port 16 has never held a registered designation on either transport (RFC 1700, Assigned Numbers, J. Reynolds and J. Postel, October 1994, already showed no well-known service for port 16). Wikipedia's list of TCP and UDP port numbers omits port 16 entirely — the table steps from port 15 to port 17 — which is consistent with the unassigned status and the lack of any documented use. One disambiguation is worth recording because it recurs in third-party port lists: the Message Send Protocol (MSP, RFC 1159 / RFC 1312) is occasionally mis-cited against port 16, but MSP is assigned to port 18, not 16, and has no association with this number. For an analyst the practical consequence is that no legitimate, standardized service should answer on 16/udp, so any host responding on it is running non-standard or undocumented software, which is itself a detection signal. Real-world exposure is minimal: SANS Internet Storm Center port telemetry for port 16 shows only isolated, low-volume scan sources and records no CVEs and no community reports against the port. UDP makes any observation harder to read than TCP — an unassigned UDP port frequently shows as open|filtered in Nmap UDP scans, because the absence of an ICMP Port Unreachable reply (often rate-limited or dropped by the host) is indistinguishable from a genuine listener. Treat a responsive 16/udp as a misconfiguration, a custom application, or a possible covert use of an obscure low port rather than a normal service.
- IANA assignment
- none — listed as Unassigned; service-name column empty, no assignee, reference field blank (no RFC cited); dual-registered Unassigned on 16/udp + 16/tcp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry lines 36–37)
- Range class
- well-known (0–1023) [Confirmed]
- IANA reference
- blank — no RFC cited in the registry (stays blank, not fabricated) [Confirmed] — IANA registry
- Prevalence
- negligible — no per-port open-frequency figure recorded for 16/udp; SANS ISC port telemetry shows only isolated low-volume scan sources [Likely] — SANS Internet Storm Center port 16 activity page
- Related ports
- 16/tcp (also Unassigned); the small/legacy low-port cluster (7, 9, 11, 13, 17, 19) that surrounds it; adjacent Unassigned ports 14 and 15
Primary use
none — no IANA-assigned protocol; RFC 1700 (1994) also listed port 16 as unassigned, so it has no historical well-known service either
Other/unofficial uses
Unknown — no standard software is documented as legitimately binding to 16/udp; Wikipedia's TCP/UDP port list omits port 16 entirely (jumps 15→17). Note that Message Send Protocol (MSP) is sometimes wrongly cited for port 16 — MSP is assigned to port 18, not 16
Security implications
no malware family, named exploit, or CVE attributed to port 16 in public threat intel checked; SANS ISC records no CVEs and no community comments for the port. Because the port is unassigned, any host answering on it is running non-standard/undocumented software (custom app, misconfiguration, or unauthorized software) and may warrant investigation as a detection signal
Exposure / scanning
very low observed scan traffic on port 16 per SANS ISC (isolated source IPs); no documented campaign, CVE, malware, or backdoor specifically targets 16/udp; low-numbered unassigned ports are probed incidentally by broad opportunistic sweeps. On UDP an unassigned port commonly shows as open|filtered in Nmap because a missing ICMP Port Unreachable (rate-limited) looks like a listener
Typically seen on
no expected legitimate listener; a responsive 16/udp is an anomaly worth investigating
- Analyst note
- There is no standardized service for port 16 — treat any open 16/udp as non-standard software and investigate; do not assume a benign default.