257
Summary
- // if you see it open
- No CVEs, honeypot data, or threat-intel reports specific to port 257 found in this pass. A low-tier port-lookup aggregator (auditmypc.com) claims no known malware/trojan association, but this is unverified and treated as weak signal. SET is widely (secondary-source) reported abandoned by ~2002 in favor of SSL/TLS-based e-commerce security, so a live port 257 today is expected to be rare/dormant and worth investigating as an anomaly.
- // analyst note
- Given SET's obsolescence, an open port 257 today is unusual and worth investigating (misconfiguration, decoy, or unrelated service squatting the port) rather than treating as routine.
About port 257/tcp.
Port 257/tcp (and its dual-registered udp counterpart) is assigned by IANA to the service name "set," with the description "Secure Electronic Transaction," and lists Donald Eastlake as both assignee and contact; the registry's reference/RFC column is blank, so no formal specification document is cited for this assignment. SET — Secure Electronic Transaction — was a payment-card security protocol developed jointly by Visa and Mastercard in the mid-1990s (with participation from Microsoft, Netscape, and IBM) to encrypt and authenticate card-not-present transactions carried over the open Internet; its first published version dates to around early 1997. Secondary industry sources commonly describe SET as effectively abandoned by the early 2000s, displaced by simpler SSL/TLS-based e-commerce security models such as 3-D Secure running over standard HTTPS, though no first-party, dated retirement announcement was located to confirm the exact year. Because SET saw limited real-world adoption even at its peak and has had no meaningful deployment for roughly two decades, port 257 is expected to be effectively dormant on the modern Internet. No CVEs, honeypot data, or threat-intelligence reporting specific to this port were found in this pass, and no current software was identified that still binds to it; a low-tier port-lookup aggregator claims no known malware association, but that claim is unverifiable and is treated as weak signal rather than fact. An analyst who observes port 257 open today should treat it as an anomaly worth investigating rather than as a normal, expected service.
- IANA assignment
set— "Secure Electronic Transaction"; reference/RFC blank; assignee/contact Donald Eastlake; dual-registered 257/tcp + 257/udp [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=257- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- the nmap-services dataset records an open-frequency of 0.0001 for 257/tcp (~0.01% of sampled hosts, catalogued there under the
fw1-mc-fwmodulelabel), about a fifth of the 0.000511 recorded for the 257/udpsetsibling — rare on both transports [Confirmed] — nmap-services dataset - Related ports
- 257/udp — the dual-registered sibling, carrying the identical service name
set, the identical description "Secure Electronic Transaction", the same assignee/contact and a likewise blank Reference column [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry. Searching the full IANA registry for the service namesetand for that assignee returns exactly these two rows, so 257/udp is the only port related to this one by registration; no companion, successor or paired SET service port is registered anywhere else in the registry [Confirmed]. The udp sibling is itself very rarely seen open in scan data (nmap-services open-frequency ≈0.000511) [Confirmed] — nmap-services dataset. For contrast, the TLS-based e-commerce security that displaced SET carries no dedicated assignment of its own and runs over 443/tcp (https, RFC 9110)[Likely] — the IANA Service Name and Transport Protocol Port Number Registry
Primary use
SET (Secure Electronic Transaction), a Visa/Mastercard-led (with Microsoft, Netscape, IBM participation) payment-card security protocol for encrypting/authenticating card-not-present transactions, first version published ~early 1997
Other/unofficial uses
the nmap-services dataset does not carry the IANA name as the primary label for this port — it lists 257/tcp as fw1-mc-fwmodule (Check Point FireWall-1 management-console module) and relegates set to the comment field, so the community catalogue treats FireWall-1 management traffic as the likelier occupant of 257/tcp than SET. This is unofficial, not a registration: searching the IANA registry returns no row whose service name contains "fw1", and Check Point's own registrations sit elsewhere in the number space — cp-cluster on 8116, checkpoint-rtm on 18241, iclid and clusterxl on 18242–18243
Security implications
no CVEs, honeypots, or threat-intel reports specific to port 257 were found; a low-tier port-lookup aggregator (auditmypc.com) claims no known malware/trojan association, but this is an unverified, weak-reliability source, not threat-intel
Typically seen on
Unknown — no current deployment data found in this pass [Unknown]
- Current/historical status
- widely reported as abandoned/decommissioned by ~2002, superseded by SSL/TLS-based e-commerce security (e.g., 3-D Secure over HTTPS); exact retirement year not confirmed by a first-party dated source [Likely] — https://paymentcloudinc.com/blog/set-protocol/
- Analyst note
- Given SET's obsolescence, an open port 257 today is unusual and worth investigating (misconfiguration, decoy, or unrelated service squatting the port) rather than treating as routine.
About port 257/udp.
Port 257/udp is registered with IANA under the service name set, described as "Secure Electronic Transaction," with assignee and contact both listed as Donald Eastlake. The registry's Reference, Registration Date, and Modification Date fields are blank for this row, so no RFC number or assignment date can be cited — those fields stay unrecorded rather than guessed. The same service name, description, and contact are dual-registered on 257/tcp in the adjacent registry row, which is typical of IANA entries from that era that reserved a name across both transports regardless of whether the protocol actually used UDP in practice. The description points to SET, the Secure Electronic Transaction protocol built by a 1996 consortium led by Visa and MasterCard (joined by GTE, IBM, Microsoft, Netscape, SAIC, Terisa Systems, RSA, and VeriSign) to secure card-not-present payment transactions over open networks. SET merged two competing efforts — Visa/Microsoft's STT and MasterCard/IBM's SEPP — into a single specification, first released in early 1997. It never reached meaningful market adoption: both merchants and cardholders needed dedicated client software and digital certificates, and the operational complexity made it commercially impractical compared to simpler SSL/TLS-based card processing that became the industry default instead. No evidence surfaced of any software still listening on UDP/257 today, nor of malware or scanning activity specific to this port, so this assignment reads as a dormant historical registry entry rather than an active service.
- IANA assignment
- service name
set, description "Secure Electronic Transaction," assignee/contact[Donald_Eastlake], dual-registered with 257/tcp (same name/description/contact) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (cached IANA registry); cross-checked live at https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=257 - IANA Reference (RFC/spec)
- blank in the registry — not recorded, not invented [Confirmed] — same IANA source above
- IANA Registration/Modification Date
- blank in the registry for this entry [Confirmed] — same IANA source above
- Range class
- well-known (0–1023) [Confirmed]
- Related ports
- 257/tcp (identical dual registration: same service name, description, assignee, contact) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Protocol background
SET (Secure Electronic Transaction) was a 1996 Visa/MasterCard-led consortium protocol (also GTE, IBM, Microsoft, Netscape, SAIC, Terisa Systems, RSA, VeriSign) merging Visa/Microsoft's STT and MasterCard/IBM's SEPP; released in early 1997; failed to gain adoption due to the complexity of required client/merchant software and certificates
Exposure/scanning prevalence
Unknown — no port-257-specific scanning or Shodan-style prevalence data found; a candidate source (SpeedGuide's port page) returned HTTP 403 and was not usable, so nothing from it is asserted [Unknown]
Malware/trojan association
Unknown / none found in sources checked [Unknown]
- Current real-world usage / listening software
- Unknown — no sourced evidence of any active service on UDP/257 was found; the assignment reads as historical/dormant [Unknown]
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| set | UDP | secure electronic transaction | 0.05% |
| fw1-mc-fwmodule | TCP | set | 0.01% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.