245
Summary
- // if you see it open
- No CVEs or advisories found for port 245; absent from commonly-tracked scan-target and bad-ports reference lists, suggesting negligible current exposure, but this is inferred from absence of evidence rather than measured.
- // analyst note
- Treat an open 245/tcp as an uncommon legacy/custom-service signal; do not assume
ttylinkchat behavior without direct verification, since the actively-maintained TTYLINK implementation actually defaults elsewhere (port 87).
About port 245/tcp.
Port 245 is registered with IANA under the service name link, description "LINK," and is dual-registered on both TCP and UDP with identical name and description on each transport (IANA Service Name and Transport Protocol Port Number Registry, rows for tcp/245 and udp/245). Like many of the low three-digit assignments from the pre-modern registration era, the entry carries no assignee, no contact, no registration date, and no RFC or other reference — the registry simply lists the bare name and description, and that blank is recorded here as blank rather than filled in with a guess. Cross-referencing common Unix and Linux /etc/services files shows the conventional alias for this port is ttylink, tying it to an old keyboard-to-keyboard chat utility lineage from the BSD services heritage. That alias needs a caveat, though: the actively-documented modern "TTYLINK" command found in amateur packet-radio TNC software (e.g., XRPi/BPQ32) defaults to TCP port 87, not 245, so the /etc/services naming for port 245 looks like a legacy convention rather than evidence that a still-maintained chat program binds to 245 today. No CVE, vendor product, or mainstream scanning report was found tied to port 245, and it does not appear on commonly-tracked scan-target or "bad ports" lists, consistent with a rarely-deployed, largely inert legacy assignment. An analyst encountering an open 245/tcp today should treat it as an uncommon, likely-legacy or custom service rather than a known-risk indicator, and verify what is actually listening rather than assuming ttylink behavior.
- IANA assignment
link— "LINK"; reference blank (no RFC cited); assignee/contact/registration date all blank; dual-registered 245/tcp + 245/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry rows 559-560; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- Unknown — no nmap-services open-frequency or scan-prevalence figure was found for this port during research [Unknown]
- Related ports
- none established by sourced research; not confirmed as part of any documented port cluster [Unknown]
Primary use
no protocol spec exists in the IANA registry beyond the bare name/description; commonly aliased in /etc/services to ttylink, an old keyboard-to-keyboard chat utility convention
Other/unofficial uses
the modern, actively-documented "TTYLINK" command in amateur packet-radio TNC software (XRPi/BPQ32) defaults to TCP port 87, not 245 — suggesting the 245 ttylink alias is a naming holdover rather than a live shared implementation
Security implications
no CVEs or vendor advisories found referencing port 245; absent from commonly-tracked scan-target and "bad/trojan ports" reference lists (e.g., garykessler.net), consistent with negligible current internet-facing footprint, though this is an inference from absence of evidence rather than a measured statistic
Typically seen on
Unknown — no sourced evidence of which systems or software currently bind to this port in practice [Unknown]
- Analyst note
- Treat an open 245/tcp as an uncommon legacy/custom-service signal; do not assume
ttylinkchat behavior without direct verification, since the actively-maintained TTYLINK implementation actually defaults elsewhere (port 87).
About port 245/udp.
Port 245/udp is registered with IANA under the service name link, described simply as "LINK," with no assignee, contact, reference RFC, or registration/modification date recorded in the registry — the entry is one of the sparse legacy rows carried since the early Internet Assigned Numbers era. The same name and description are dual-registered on 245/tcp, with all the same optional columns left blank on that row too, so IANA itself gives almost nothing beyond the bare name-to-number mapping. Cross-referencing common Unix/Linux /etc/services files shows the conventional alias for this port is ttylink, tying it to an old keyboard-to-keyboard chat utility lineage from the BSD write/talk heritage — one user sends a short message that pops up directly on another logged-in user's terminal. That alias needs a caveat, though: the actively-documented modern "TTYLINK" command found in amateur packet-radio TNC software (e.g., XRPi/BPQ32) defaults to port 87, not 245, and never mentions 245 anywhere, so the /etc/services naming for port 245 looks like a legacy convention rather than evidence of a still-maintained program bound to 245 today. Separately, the ttylinkd daemon shipped in the ax25-tools package (spawned via inetd/ax25d, routing through the host's talkd, and supporting AX.25/NET-ROM/ROSE amateur packet radio) is documented by its manpage without any port number, transport, or /etc/services reference at all — so while it is plausibly the daemon behind the ttylink name, no consulted source ties it specifically to port 245 or to UDP. No mainstream commercial or consumer software was found bound to this port. No malware or trojan association turned up when checked against known "suspicious port" reference lists, but that absence is a sourced check, not an exhaustive guarantee, and no internet-wide exposure/scanning data was located for this specific port.
- IANA assignment
link— "LINK"; port 245, transport udp; reference/assignee/contact/dates all blank in the registry [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 560; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.txt- Range class
- well-known (0–1023) [Confirmed]
- Dual registration
- the identical name
link/ descriptionLINKis also registered on 245/tcp, with the same blank optional columns [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 559 - IANA reference/RFC
- none listed — left blank, not fabricated [Confirmed] — IANA registry
- Prevalence / exposure scanning
- nmap-services observed open-frequency 245/udp ≈ 0.000626 — very low (roughly 6 in 10,000 scanned hosts in the nmap-services sample); the paired 245/tcp row carries a frequency of 0 (never observed open in the same sample) [Confirmed] — nmap-services dataset. No other quantified scan-telemetry or exposure-writeup data was located for this port this pass [Unknown]
- Related ports
- 517/udp (talk) and 518/udp (ntalk) — the plausible
ttylinkddaemon's stated role is to bridge ttylink messages through to the host's talkd service, though no source ties this specifically to port 245 [Likely] — https://manpages.debian.org/bullseye/ax25-tools/ttylinkd.8.en.html
Primary use
no protocol spec exists in the IANA registry beyond the bare name/description; commonly aliased in /etc/services to ttylink, an old keyboard-to-keyboard chat utility convention (write/talk-like)
link 245/udp ttylink)Other/unofficial uses
the modern, actively-documented "TTYLINK" command in amateur packet-radio TNC software (XRPi/BPQ32) defaults to port 87 and never mentions port 245 anywhere — suggesting the 245 ttylink alias is a naming holdover rather than a live shared implementation at 245
Common software
ttylinkd, distributed as part of ax25-tools / amateur-radio networking stacks on Linux, is the plausible daemon behind the ttylink name; its manpage documents inetd/ax25d spawning and talkd routing but names no port number, no transport, and no /etc/services mapping, so it is not confirmed to bind port 245 or speak UDP
Typically seen on
legacy/niche Unix systems carrying the /etc/services ttylink alias; no source confirms current deployment on mainstream servers [Likely]
- Known malware association
- none found against Gary Kessler's "Bad Ports" list or Trend Micro's trojan-port glossary; sourced absence, not an exhaustive negative [Likely] — https://www.garykessler.net/library/bad_ports.html, https://docs.trendmicro.com/all/ent/officescan/v10.6/en-us/osce_10.6_sp1_olh/gls_trojan_port.html
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| link | UDP | — | 0.06% |
| link | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.