192
Summary
- // if you see it open
- No CVE or malware family documented as specifically targeting this port; scan activity consistent with generic internet background noise rather than targeted exploitation.
About port 192/tcp.
Port 192/tcp is registered with IANA under the service name osu-nms, described as "OSU Network Monitoring System," with assignee and contact both listed as Doug Karl. The registry entry carries no RFC or other reference, and the Registration Date, Modification Date, Service Code, and Unauthorized Use Reported columns are all blank in the source — none of those are invented here. The name points to network-monitoring tooling associated with Ohio State University, but no vendor specification, protocol document, or maintained software package describing how osu-nms actually communicates on this port could be located; it appears to be one of the many IANA-registered names from the 1990s–2000s era of academic and vendor network tools that never accumulated public documentation beyond the registry line itself. The port is dual-registered on UDP: 192/udp carries an identical service name, description, assignee, and contact, with the same set of blank fields, meaning whatever osu-nms was, it was registered to use both transports. Passive-scanning data from SANS Internet Storm Center shows the port sits at a "green" (low) threat level, with only sporadic single- or low-double-digit daily scan hits from scattered source IPs — consistent with generic internet background noise rather than targeted probing, and no CVE or malware family is documented as specifically abusing this port. One unverified, undated community forum comment associates UDP/192 with Apple AirPort Base Station PPP status/discovery traffic in some configurations; this is anecdotal and not corroborated by an Apple specification, so it is not treated as established fact. Overall, 192/tcp is a legacy, lightly-documented IANA registration with no confirmed modern real-world usage pattern and no elevated security profile beyond ordinary opportunistic scanning.
- IANA assignment
osu-nms— "OSU Network Monitoring System"; reference (blank — no RFC cited in registry); assignee/contact Doug Karl; dual-registered 192/tcp + 192/udp with identical fields [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 470-471 (mirrors https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)- Range class
- well-known (0–1023)
- Registration/modification dates, IANA reference, service code, unauthorized-use flag
- all blank in the IANA source, left null rather than fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 470
- Prevalence/exposure
- SANS ISC reports a "green" (low) threat status as of the 2026-07-11 (Pacific) check, with sporadic low single/double-digit daily scan counts from scattered sources — consistent with generic background scanning, not targeted activity; this is a live day-to-day snapshot, not a fixed historical figure[Likely] — https://isc.sans.edu/data/port/192
- Related ports
- 192/udp (identical dual registration, same assignee/contact, same blank fields) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 471
Primary use
registered network-monitoring service name; no protocol specification, vendor document, or maintained software describing actual wire behavior could be found
Other/unofficial uses
one unverified, undated SANS ISC forum comment associates UDP/192 with Apple AirPort Base Station PPP status/discovery traffic in some configurations; not corroborated by a vendor spec
Security implications
no CVE or malware family documented as specifically targeting this port; no elevated risk profile beyond ordinary opportunistic internet scanning
Typically seen on
no confirmed real-world deployment pattern identified [Unknown]
About port 192/udp.
Port 192/udp is registered with IANA under the service name osu-nms, described as "OSU Network Monitoring System," with assignee and contact listed as Doug Karl. The same service name and description are dual-registered on 192/tcp, and both the Registration Date and Reference columns are blank in the IANA registry — there is no RFC or other reference document cited for this assignment, and no dated origin is recorded, which is common for very old, pre-modern-registry-format entries near the bottom of the system-port range (0–1023). "OSU" here almost certainly refers to Ohio State University, consistent with the era of university-originated network-monitoring tooling on the early Internet, though IANA's registry itself does not spell out the institutional affiliation. No mainstream, currently maintained software or daemon is documented as actively implementing OSU-NMS today; secondary port-lookup aggregators (SpeedGuide, AuditMyPC, TCP-UDP-Ports) simply reproduce the IANA assignment without naming a live implementation. One secondary source (AuditMyPC) notes port 192 has historically appeared on generic legacy virus/Trojan port lists, but frames this as historical/generic port-list flagging rather than a confirmed, named malware family or an active exploitation campaign tied specifically to this port. No CVE or scanning-campaign report specific to 192/udp was located. Net effect: a legitimate, decades-old system-port assignment with essentially no modern real-world footprint — traffic seen on this port today is more likely coincidental, misconfigured, or a legacy holdover than genuine OSU-NMS activity.
- IANA assignment
osu-nms— "OSU Network Monitoring System"; reference (blank — no RFC cited in IANA registry); assignee/contact Doug Karl; dual-registered 192/tcp + 192/udp [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt- Registration/modification date
- blank in the IANA registry; not fabricated [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
- Range class
- well-known (0–1023) [Confirmed]
- Prevalence / typically seen on
- nmap-services observed open-frequency 192/udp ≈ 0.004168 — very low (roughly 4 in 1,000 scanned hosts in the nmap-services sample) [Likely] — nmap-services dataset; no deployment data identifies what is still listening on those hosts [Unknown]
- Related ports
- 192/tcp — the same
osu-nmsservice, dual-registered by IANA with an identical description and the same assignee/contact, and likewise carrying blank Reference and Registration Date columns [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry. Searching the full IANA registry for the service nameosu-nmsand for that assignee returns exactly these two rows, so 192/tcp is the only port related to this one by registration; no companion, successor, or commonly-paired service port is documented for OSU-NMS in the registry or in the secondary sources consulted for this entry [Confirmed]. The tcp side is far rarer in practice than the udp side (nmap-services open-frequency ≈0.000013 vs ≈0.004168)[Likely] — nmap-services dataset
Primary use
legacy OSU Network Monitoring System protocol (OSU-NMS); no modern mainstream implementation documented
Common software
Unknown / none well-documented currently active
Security implications
some legacy/generic virus-port-list flagging noted by a secondary source, not tied to a named malware family or confirmed campaign; no CVE found
- Analyst note
- essentially never legitimately observed today; treat an active 192/udp as an anomaly, legacy holdover, or misconfiguration rather than genuine OSU-NMS traffic.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| osu-nms | UDP | OSU Network Monitoring System | 0.42% |
| osu-nms | TCP | OSU Network Monitoring System | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.