Network port detail · UDP/TCP

263

Hdap
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No CVEs, scanning prevalence, honeypot reports, or threat-intel mentions found for port 263 in this research pass. No known software binds to this port. Insufficient data to characterize risk beyond the general caution that an undocumented open well-known port merits investigation.
[ 01 ] — Context

About port 263/tcp.

Updated  ·  Confidence: Medium

Port 263/tcp is registered with IANA under the service name hdap, with the plain-text description "HDAP" and no expanded protocol name given in the registry itself. The assignment is credited to a contact/assignee recorded only as "[Troy_Gau]" — the registry's bracketed shorthand for an individual assignee rather than an organization — and the Reference column, which would normally point to a defining RFC or Internet-Draft, is blank. No registration or modification date is published for this entry, which is typical of many pre-2000s or informally-assigned IANA rows rather than an indication of anything unusual. The port is dual-registered: 263/udp carries the identical service name, description, and assignee, with the same blank supporting fields, meaning the registration applies symmetrically to both transports rather than being TCP-specific. Outside of the registry, no independent documentation — IETF draft, vendor specification, open-source implementation, or credible secondary reference — could be found clarifying what "HDAP" expands to or what protocol traffic on this port actually looks like; the informal expansion "Hybrid Directory Access Protocol" appears only on unsourced third-party port-list aggregator sites and is not corroborated by any primary source, so it is treated as unverified. Likewise, no evidence of real-world software binding to port 263, no CVEs, and no scanning/honeypot/threat-intel prevalence data were found in this pass. As a well-known port (range 0–1023) with essentially no public documentation trail beyond the bare IANA row, 263/tcp should be treated by an analyst as a low-information, rarely-seen assignment: an observed connection on this port is not a recognized fingerprint for any known product, and its significance (if any) would have to be assessed from the actual traffic rather than from the port number.

IANA assignment
hdap — "HDAP"; reference (blank — no RFC/draft cited in IANA registry); assignee/contact "[Troy_Gau]" [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Dual registration
263/udp registered identically (same service name, description, assignee, blank supporting fields) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed] — port number itself
Registration/modification date
not published in the IANA registry for this entry (blank, not fabricated) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; IANA registry

Protocol expansion "Hybrid Directory Access Protocol"

appears only on unsourced secondary port-list sites, no primary (IETF/vendor) confirmation found

[Unknown] — http://www.t1shopper.com/tools/port-number/263/; https://www.speedguide.net/port.php?port=263

Common software/implementations

none identified in this research pass [Unknown]

Typically seen on

no data found to characterize typical hosts [Unknown]

Security/exposure notes
no CVEs, scanning prevalence, or threat-intel mentions found; absence of findings is not proof of absence [Unknown]
[ 02 ] — Context

About port 263/udp.

Updated  ·  Confidence: Medium

Port 263/udp is registered with IANA under the service name hdap, with the description field holding only the bare acronym "HDAP" — the registry gives no expansion of what the letters stand for. The assignee and contact are both listed as "[Troy_Gau]"; an independent port-lookup mirror ties that contact to an @zyxel.com address, suggesting the registration originated with Zyxel, but no Zyxel product page, knowledge-base article, or technical write-up describing an "HDAP" feature turned up in this pass. The registry's Reference (RFC), Registration Date, and Modification Date columns are all blank for this entry, and they are reported here as blank rather than guessed at. Port 263 is dual-registered: the identical service name, description, assignee, and contact appear on both the tcp and udp rows, with every trailing column empty on both. Beyond the bare registry listing, there is little public signature for this port: no common software or open-source implementation was identified as using it, and no Shodan/Censys-specific exposure statistics or scanning-campaign write-ups surfaced. One lower-authority port-information mirror does explicitly note no known virus/trojan association for UDP port 263. Taken together, this reads as a legitimate but essentially dormant IANA well-known-port registration — assigned to a named individual/vendor contact, undocumented in public sources, and not observed in real-world deployment or abuse reporting, rather than an actively used or notorious service.

IANA assignment
hdap — description "HDAP" (no expansion given); reference blank; assignee/contact [Troy_Gau]; dual-registered 263/tcp + 263/udp under the same service name, both rows blank on all trailing columns [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (and :589 for the tcp row); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services observed open-frequency 263/udp ≈ 0.000544 (very low — roughly 5 in 10,000 scanned hosts in the nmap-services sample) [Confirmed] — nmap-services dataset; the dual-registered 263/tcp row records 0.000000 in the same dataset, so what little observed activity exists sits on the UDP side
[Confirmed] — nmap-services dataset
Related ports
263/tcp (identical dual registration, same service name/assignee, both blank on remaining fields) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry

Primary use

Unknown — no RFC, spec, or vendor documentation found that spells out what HDAP does or stands for; do not treat any expansion (e.g. "Host/Hybrid/Home Directory Access Protocol") as fact [Unknown]

Other/unofficial uses

possible Zyxel affiliation via the registrant's contact address, but no specific Zyxel feature or product documentation located

[Likely] — http://www.t1shopper.com/tools/port-number/263/

Security implications

one independent, lower-authority port-info mirror explicitly reports no known virus/trojan association for UDP 263; no dedicated Shodan/Censys exposure data or abuse/honeypot reporting specific to port 263 was found

[Likely] — https://www.auditmypc.com/udp-port-263.asp

Typically seen on

Unknown — no evidence of real-world deployment or common software using this port was found [Unknown]

Analyst note
an essentially dormant, undocumented IANA registration with a named but unverified vendor tie; no observed malware association in the sources checked, but also no evidence of legitimate active deployment — treat a responsive port 263 as unusual and worth investigating rather than assuming either benign or malicious intent.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
hdap UDP 0.05%
hdap TCP 0.00%
IANA name
hdap
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.