2
Summary
- // if you see it open
- No CVEs or targeted exploits specific to CompressNET. Negligible real-world traffic. Internet-wide scanners do sweep low-numbered ports including port 2, so any service bound here is visible to opportunistic scanners. Primary risk is an accidental misconfiguration binding to port 2 rather than exploitation of CompressNET itself. The 2025-02-13 IANA de-assignment to Reserved means no new legitimate service should register here.
- // analyst note
- An open port 2 is statistically rare and has no legitimate modern use — treat as an anomaly and investigate.
About port 2/tcp.
Port 2/tcp was historically registered with IANA as compressnet, the "Management Utility" channel of CompressNET — a proprietary in-transit packet-compression scheme. Port 2 was the management/control channel and port 3 was the companion compression-process channel. The assignment is attributed to Bernie Volz at Process Software Corporation (Framingham, MA), the VAX/VMS networking vendor that shipped the TCPware stack, and it first appears in the IANA Assigned Numbers listing in RFC 1340 (July 1992). No specification document for the protocol itself was ever published beyond the port-number listing — the IANA Reference column for this row is blank, and there is no RFC describing CompressNET's wire format. The protocol has no known production deployment, open-source implementation, or documented client/server in publicly available sources, so for over three decades the registration was effectively dormant. On 2025-02-13 IANA formally de-assigned ports 2 and 3 on both TCP and UDP, removing the compressnet service name and moving them to Reserved status with the registry note "De-assigned, previously compressnet" attributed to Bernie Volz. For an analyst, port 2/tcp matters almost entirely as a curiosity and an anomaly signal: there is no legitimate modern service that should bind here, no CVE or targeted exploit specific to CompressNET, and negligible legitimate traffic. Internet-wide scanners (Shodan, Masscan full-range sweeps) do touch low-numbered ports including port 2, so anything answering on it is worth investigating as a misconfiguration, decoy, or backdoor rather than a normal service.
- IANA assignment
- now Reserved (de-assigned 2025-02-13); previously
compressnet— "Management Utility (CompressNET)"; Reference field blank (no RFC cited in IANA registry row); previous assignee Bernie Volz; dual-registered 2/tcp + 2/udp[Confirmed] — IANA Service Name and Transport Protocol Port Number Registry - Range class
- well-known (0–1023)
- Related ports
- 3/tcp (compressnet compression-process channel, de-assigned the same day)
Primary use (historical)
CompressNET Management Utility — the management/control channel of a proprietary in-transit packet-compression protocol; port 3 was the compression-process channel
Other/unofficial uses
none documented; no open-source implementation, client, or server found in public sources
Security implications
no CVEs and no targeted exploits specific to CompressNET; negligible legitimate traffic; low-number port sweeps (Shodan, Masscan) do cover port 2, so any bound service is visible to opportunistic scanners; primary risk is an accidental misconfiguration binding to port 2, not exploitation of CompressNET itself; Reserved status as of 2025 means no new legitimate service should register here
Typically seen on
nothing legitimate today; a responsive port 2 is an anomaly / possible misconfiguration, decoy, or backdoor
- First appeared
- RFC 1340, July 1992 [Confirmed] — datatracker.ietf.org/doc/html/rfc1340
- Registrant (historical)
- Bernie Volz, Process Software Corporation (maker of TCPware, a VAX/VMS networking stack) [Confirmed] — RFC 1340; connected.app
- De-assignment
- 2025-02-13 — status changed from Assigned to Reserved on both 2/tcp and 2/udp [Confirmed] — IANA registry
- Analyst note
- An open port 2 is statistically rare and has no legitimate modern use — treat as an anomaly and investigate.
About port 2/udp.
Port 2/udp is currently listed in the IANA Service Name and Transport Protocol Port Number Registry as Reserved with no service name, no assignee, no contact, and a blank reference field. The registry records that the entry was de-assigned on 2025-02-13; prior to that date it was registered as compressnet (assigned by Bernie Volz). The same de-assignment applies symmetrically to 2/tcp, which is dual-registered and carries the identical status (Reserved, de-assigned 2025-02-13, previously compressnet). The historical "compressnet" assignment traces back to the early IANA/RFC assigned-numbers lineage: RFC 1340 (Assigned Numbers, July 1992) listed port 2 with the UDP variant described as "Compression Process" and the TCP variant as "Management Utility" — a legacy proprietary network-compression and management protocol that was never widely deployed. There is no current RFC reference in the IANA registry entry; the Reference column is blank and stays blank (the only documentary trace is the historic RFC 1340 assigned-numbers document, not a normative reference cited by IANA). For an analyst, port 2/udp carries little practical exposure: no modern software is documented as using it, no known malware or trojan is associated with it (AuditMyPC lists no trojan for UDP port 2), and there are no documented mass-scanning campaigns specifically targeting it as of 2026-06-19. Because UDP is connectionless, scan-state determination for low UDP ports is unreliable without ICMP port-unreachable responses, and Nmap does probe port 2 within its default low-port UDP scan list, so the port may appear in scan logs without indicating any live service. Standard least-privilege firewall policy should block inbound traffic to it. Treat a responsive port 2/udp as an anomaly worth investigating rather than a normal service.
- IANA assignment
- Reserved — de-assigned 2025-02-13; previously
compressnet(assigned by Bernie Volz); service name now blank; reference field blank [Confirmed] — IANA Service Names and Port Numbers registry (the IANA Service Name and Transport Protocol Port Number Registry line 7) - Range class
- well-known (0–1023) [Confirmed] — port number 2
- IANA reference
- blank — no RFC cited in the current IANA registry entry; only historic documentary trace is RFC 1340 (not a normative IANA reference) [Confirmed] — IANA registry; RFC 1340
- Dual registration
- 2/tcp is dual-registered with the identical status (Reserved, de-assigned 2025-02-13, previously compressnet) [Confirmed] — IANA registry (csv line 6)
- Modification date
- 2025-02-13 (de-assignment date recorded in the registry) [Confirmed] — IANA registry (csv line 7)
- Registration date
- null — no original registration date present in the current registry entry [Confirmed] — IANA registry (csv line 7)
Primary use
historically "Compression Process" (UDP variant of compressnet) per RFC 1340 (July 1992); no active modern use; now Reserved
Common software
Unknown — no actively maintained software identified using port 2/udp; compressnet was proprietary with no documented open-source or vendor implementations [Unknown]
Security implications
low practical risk — no known active service, no documented malware/trojan association (AuditMyPC lists none); connectionless UDP would expose any reflective service to spoofing/amplification recon, but none is standard here; block inbound by default
- Scanning notes
- Nmap includes port 2 in its default UDP low-port target list; no high-frequency campaigns specifically targeting 2/udp documented as of 2026-06-19; UDP scan state is unreliable without ICMP unreachable replies [Likely] — https://nmap.org/book/scan-methods-udp-scan.html
- Analyst note
- An open/responsive port 2/udp is statistically rare and carries no legitimate standard service today — investigate as an anomaly, decoy, or misconfiguration.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| compressnet | UDP | Management Utility | 0.18% |
| compressnet | TCP | Management Utility | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.