202
Summary
- // if you see it open
- RFC 6760 (2013) states NBP predates modern security norms and lacked authentication/access-control mechanisms. AppleTalk is retired and not carried over modern IP networks, so a live port 202 today most plausibly reflects legacy hardware rather than active use; no port-202-specific CVE or scanning-campaign reporting found.
About port 202/tcp.
Port 202 is registered with IANA as at-nbp, "AppleTalk Name Binding," and is dual-registered on both TCP and UDP with identical service name and description on each line; the Assignee, Contact, Registration Date, Modification Date, Reference, Service Code, and Unauthorized Use Reported columns are all blank in the registry, so those attributes are reported here as genuinely unknown rather than guessed. NBP (Name Binding Protocol) was part of Apple's AppleTalk suite (built on the Datagram Delivery Protocol) and served as AppleTalk's dynamic name-to-address resolution layer: a device registered a human-readable name for a service at startup, and clients performed NBP lookups or broadcasts to resolve that name to a network address — functionally a rough AppleTalk-era analog of combined ARP and DNS-SD. AppleTalk itself is obsolete: Apple dropped support after Mac OS X 10.5 Leopard, with Snow Leopard (10.6, 2009) shipping without it, so the suite was fully superseded by IP-based discovery (mDNS/DNS-SD, i.e. Bonjour). RFC 6760 (2013), written to define requirements for an NBP successor, explicitly calls out that NBP predates modern security expectations and lacked authentication or access-control mechanisms. Because AppleTalk is retired and not carried over modern IP networks, a live port 202 today most plausibly reflects legacy hardware (vintage Mac servers, old AppleTalk-capable printers or routers) rather than active use, and no dated evidence of current internet-wide scanning campaigns or CVEs specific to this port was found in this research pass.
- IANA assignment
at-nbp— "AppleTalk Name Binding"; dual-registered 202/tcp + 202/udp, identical service name and description on both rows; Assignee/Contact/Registration Date/Modification Date/Reference/Service Code/Unauthorized Use Reported all blank in the registry [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry lines 490-491; cross-checked against https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=202- IANA reference/RFC
- blank in the registry — not backfilled with a guessed RFC [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry lines 490-491
- Range class
- well-known (0–1023)
- Prevalence
- nmap-services observed open-frequency 202/tcp ≈ 0.000025 (very low — roughly 2 to 3 in 100,000 scanned hosts in the nmap-services sample); the dual-registered 202/udp side is higher at ≈ 0.000445, which is expected given NBP is a DDP/datagram protocol [Confirmed] — nmap-services dataset. The figure records scan-observed openness on the port number, not surviving AppleTalk NBP traffic; no Shodan/Censys telemetry specific to 202 was located [Unknown]
- Current status
- obsolete/deprecated; Apple dropped AppleTalk support after Mac OS X 10.5, with 10.6 Snow Leopard (2009) shipping without it, superseded by mDNS/DNS-SD (Bonjour) [Confirmed] — https://en.wikipedia.org/wiki/AppleTalk; https://datatracker.ietf.org/doc/rfc6760/
- Related ports
- 201/tcp,udp (AppleTalk Routing Maintenance); 204/tcp,udp (AppleTalk Echo) — same AppleTalk suite [Likely] — https://whatportis.com/ports/201_appletalk-routing-maintenance
Primary use
Name Binding Protocol (NBP), AppleTalk's dynamic name-to-address resolution service; devices register names, clients resolve them via NBP lookup/broadcast
Other/unofficial uses
legacy Apple networking stack (classic Mac OS, early Mac OS X AppleTalk/File Sharing) and AppleTalk-capable third-party hardware (older LaserWriter-class printers, routers/gateways with AppleTalk routing)
Security implications
RFC 6760 states NBP "was developed in an era when little consideration was given to security issues" and lacked authentication; AppleTalk is retired and not routed over modern IP networks, so a live port 202 today most plausibly indicates legacy hardware rather than an active service; no port-202-specific CVE found
Typically seen on
legacy/vintage Mac OS servers, old AppleTalk-capable printers or routers; otherwise anomalous on a modern network [Likely]
Malware associations
Unknown — no sourced reporting found in this pass [Unknown]
About port 202/udp.
Port 202 is registered with IANA as at-nbp, "AppleTalk Name Binding," and is dual-registered on both TCP and UDP with an identical service name and description on each row; the Assignee, Contact, Registration Date, Modification Date, Reference, Service Code, and Unauthorized Use Reported columns are all blank in the registry for the UDP row, so those attributes are reported here as genuinely unknown rather than guessed. NBP (Name Binding Protocol) was part of Apple's AppleTalk suite, built on the Datagram Delivery Protocol, and served as AppleTalk's dynamic name-to-address resolution layer: a device registered a human-readable name for a service at startup, and clients performed NBP lookups or broadcasts over UDP-carried AppleTalk-over-IP (or historically DDP) transport to resolve that name to a network address — functionally a rough AppleTalk-era analog of combined ARP and DNS-SD, with the datagram/broadcast style of lookup traffic a natural fit for UDP specifically. AppleTalk itself is obsolete: Apple dropped support after Mac OS X 10.5 Leopard, with Snow Leopard (10.6, 2009) shipping without it, so the suite was fully superseded by IP-based discovery (mDNS/DNS-SD, i.e. Bonjour). RFC 6760 (2013), written to define requirements for an NBP successor, explicitly calls out that NBP predates modern security expectations and lacked authentication or access-control mechanisms. Because AppleTalk is retired and UDP scanning itself is inherently ambiguous (a dropped packet looks identical to a closed port), a live port 202/udp today most plausibly reflects legacy hardware (vintage Mac servers, old AppleTalk-capable printers or routers) rather than active use; one non-authoritative aggregator explicitly reports no trojan/virus association for this port, and no CVE specific to 202/udp was found in this research pass.
- IANA assignment
at-nbp— "AppleTalk Name Binding"; dual-registered 202/tcp + 202/udp, identical service name and description on both rows; Assignee/Contact/Registration Date/Modification Date/Reference/Service Code/Unauthorized Use Reported all blank in the registry [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 491 (udp), cross-checked against line 490 (tcp); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=202- IANA reference/RFC
- blank in the registry — not backfilled with a guessed RFC [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 491
- Range class
- well-known (0–1023)
- Prevalence/exposure
- nmap-services observed open-frequency 202/udp ≈ 0.000445 (very low — roughly 4 in 10,000 scanned hosts in the nmap-services sample); the dual-registered 202/tcp side is rarer at ≈ 0.000025 [Confirmed] — nmap-services dataset; no Shodan, Censys, or other first-party scan-telemetry source specific to 202/udp was located in this pass, and UDP scan results are inherently ambiguous (dropped packets vs. closed ports) [Unknown]
- Current status
- obsolete/deprecated; Apple dropped AppleTalk support after Mac OS X 10.5, with 10.6 Snow Leopard (2009) shipping without it, superseded by mDNS/DNS-SD (Bonjour) [Confirmed] — https://en.wikipedia.org/wiki/AppleTalk; https://datatracker.ietf.org/doc/rfc6760/
- Related ports
- 202/tcp (identical at-nbp dual registration); 201/tcp,udp (AppleTalk Routing Maintenance); 204/tcp,udp (AppleTalk Echo) — same AppleTalk suite [Likely] — https://whatportis.com/ports/201_appletalk-routing-maintenance
Primary use
Name Binding Protocol (NBP), AppleTalk's dynamic name-to-address resolution service; devices register names, clients resolve them via NBP lookup/broadcast, with UDP carrying the datagram-style lookup/broadcast traffic
Other/unofficial uses
legacy Apple networking stack (classic Mac OS, early Mac OS X AppleTalk/File Sharing) and AppleTalk-capable third-party hardware (older LaserWriter-class printers, routers/gateways with AppleTalk routing); no modern software found still using it
Security implications
RFC 6760 states NBP "was developed in an era when little consideration was given to security issues" and lacked authentication; AppleTalk is retired and not routed over modern IP networks, so a live 202/udp today most plausibly indicates legacy hardware rather than an active service; no port-202/udp-specific CVE found
Typically seen on
legacy/vintage Mac OS servers, old AppleTalk-capable printers or routers; otherwise anomalous on a modern network [Likely]
Malware associations
none confirmed; one non-authoritative aggregator (auditmypc.com) marks UDP port 202 as not trojan/virus-flagged in its own table; no CVE or named malware family found
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| at-nbp | UDP | AppleTalk Name Binding | 0.04% |
| at-nbp | TCP | AppleTalk Name Binding | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.