Network port detail · UDP/TCP

193

Srmp
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No malware or CVE association found in this pass; AuditMyPC's port-threat database marks 193 as carrying no known virus/trojan, and GRC's Port Authority lists no threat notes. Absence of documented exploitation does not confirm the port is inherently safe if found open.
// analyst note
A responding 193/tcp is uncommon and worth investigating as a fingerprint or anomaly given the near-absence of modern documentation, rather than assumed to be a known, actively-exploited service.
[ 01 ] — Context

About port 193/tcp.

Updated  ·  Confidence: Medium

Port 193/tcp is registered with IANA under the service name srmp, described as "Spider Remote Monitoring Protocol," with assignee and contact listed as Ted J. Socolofsky. The registry's reference column is blank for this entry — no RFC or other standards-track document is cited, so no protocol specification should be inferred or invented. The assignment is dual-registered: both 193/tcp and 193/udp carry the identical service name and description in the IANA Service Name and Transport Protocol Port Number Registry, meaning the protocol was defined (or reserved) to run over either transport rather than being TCP-specific. Beyond the bare registry entry, independent documentation is thin. Secondary port-lookup mirrors associate the "Spider" name with Spider Systems, a UK networking vendor historically known for terminal-server and X.25 products, but no current, independently verified software implementation of srmp could be confirmed in this pass, so that association is treated as unconfirmed background rather than fact. No malware or CVE association turned up: a widely used port-threat mirror explicitly flags the port as carrying no known virus/trojan activity, and another port-lookup reference lists no threat notes. The port is also absent from Wikipedia's well-known-ports table and shows no documented modern scanning or exploitation trend, consistent with a rarely-deployed legacy assignment rather than an actively targeted service. Analysts encountering a live 193/tcp responder should treat it as unusual and worth fingerprinting rather than assuming a known risk profile, given how little modern evidence of real-world use exists.

IANA assignment
srmp — "Spider Remote Monitoring Protocol"; reference field blank in the registry; assignee/contact Ted J. Socolofsky; dual-registered 193/tcp + 193/udp [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services observed open-frequency 193/tcp ≈ 0.000025 (very low — roughly 2 to 3 in 100,000 scanned hosts in the nmap-services sample); the dual-registered 193/udp side is higher at ≈ 0.000412 [Confirmed] — nmap-services dataset. The figure records scan-observed openness on the port number, not confirmed srmp use, and corroborates the rarely-used-legacy-assignment reading [Confirmed]
Related ports
none specifically documented as related in sources reviewed [Unknown]

Primary use

Spider Remote Monitoring Protocol per IANA name/description; no RFC or protocol spec is cited by the registry, so the operational details of the protocol are Unknown [Confirmed name/description, Unknown mechanism] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Other/unofficial uses

secondary mirrors loosely associate the "Spider" naming with Spider Systems (UK networking vendor); no current, independently verified software implementation confirmed

[Unknown] — https://www.speedguide.net/port.php?port=193, https://www.auditmypc.com/tcp-port-193.asp

Security implications

no malware/CVE association found; one port-threat mirror marks it "Virus/Trojan: No," another lists no threat notes; absence of evidence, not a proof of safety

[Likely] — https://www.auditmypc.com/tcp-port-193.asp, https://www.grc.com/port_193.htm

Typically seen on

not documented in Wikipedia's well-known-ports table or other current sources reviewed; appears to be a rarely-used legacy assignment with low modern exposure

[Likely, absence-based inference] — https://en.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers, https://www.grc.com/port_193.htm
Analyst note
A responding 193/tcp is uncommon and worth investigating as a fingerprint or anomaly given the near-absence of modern documentation, rather than assumed to be a known, actively-exploited service.
[ 02 ] — Context

About port 193/udp.

Updated  ·  Confidence: Medium

Port 193/udp is registered with IANA under the service name srmp, described as "Spider Remote Monitoring Protocol," with Ted J. Socolofsky listed as both assignee and contact. The registration is one of the many legacy entries IANA carried over from the earliest Internet Assigned Numbers lists: it has no Reference (RFC) column populated, no Registration Date, and no Modification Date — all four of those metadata columns are blank in the current registry, not merely undocumented. The same service name, description, and assignee appear identically at 193/tcp, so the assignment is dual-registered across both transports rather than udp-specific. "Spider" here almost certainly refers to a proprietary monitoring product rather than a web-crawling context, but no surviving specification, vendor documentation, or public protocol description for SRMP could be located, so its wire format and actual field usage remain unknown. No CVE, malware family, or documented exploitation campaign tied specifically to port 193 was found in this research pass; a single port-lookup aggregator (AuditMyPC) surfaces generic templated "may be used by malicious software" language that is boilerplate common to most of its port pages rather than a documented finding, so it is not treated as a real security signal. In practice, a live responder on 193/udp today would be unusual and worth investigating on its own merits rather than assumed to be SRMP traffic, given how obscure and undocumented the original protocol is.

IANA assignment
srmp — "Spider Remote Monitoring Protocol"; assignee/contact Ted J. Socolofsky; Reference field blank (no RFC cited) [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Registration/modification dates
blank in the registry for this entry — not populated with a placeholder [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
Dual registration
identical entry (name, description, assignee, blank metadata) also present at 193/tcp [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt
Range class
well-known (0–1023) [Confirmed]
Related ports
193/tcp (identical dual registration) [Confirmed]

Protocol specification/implementation

no surviving spec or documented software found; SRMP wire format unknown [Unknown]

Security implications

no port-specific CVE or malware family found; one aggregator site (AuditMyPC) shows generic templated "may be used by malware" language common across its port pages, not treated as a specific finding

[Likely/low-confidence] — https://www.auditmypc.com/udp-port-193.asp

Typically seen on

no evidence of live/common exposure found; treat any responder as anomalous [Unknown]

// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
srmp UDP Spider Remote Monitoring Protocol 0.04%
srmp TCP Spider Remote Monitoring Protocol 0.00%
IANA name
srmp
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.