265
Summary
- // if you see it open
- No known CVEs, malware associations, or exploit activity specifically targeting 265/tcp. X-Bone is a defunct research system with no current production footprint, so an unexpected open 265/tcp is atypical and merits investigation rather than being assumed benign.
- // analyst note
- A responsive 265/tcp is uncommon and not tied to any current mainstream service; verify context before assuming either the X-Bone research lineage or the unconfirmed Check Point/SMTPS claims.
About port 265/tcp.
Port 265/tcp is registered with IANA as x-bone-ctl with the description "X-Bone CTL," assignee and contact Joe Touch, and blank Registration Date, Modification Date, and Reference columns; the entry is dual-registered on 265/tcp and 265/udp with otherwise identical rows. X-Bone was a DARPA-funded overlay-network research project developed at USC's Information Sciences Institute (ISI) in the late 1990s through the early 2000s, aimed at automating the deployment and management of virtual private overlay networks across shared physical infrastructure — a VPN-like automatic-provisioning system rather than a single fixed protocol spec published as an RFC. The IANA reference field being blank is consistent with this: no RFC or standards-track document was ever assigned to the port, so nothing is cited there. X-Bone itself does not appear to be in active production use today; it reads as a completed research effort rather than a currently deployed service. Two secondary, lower-authority claims turned up in general port-database sites: one associates 265/tcp with Check Point FireWall-1/VPN-1's "Public Key Transfer Protocol," and another claims use for SMTP-over-SSL/TLS — the latter conflicts with the conventional SMTPS port 465 and is not corroborated by any primary source. No CVEs, malware families, or documented scanning/honeypot activity specifically targeting 265/tcp were found; that absence is itself an unknown, not a clean bill of health.
- IANA assignment
x-bone-ctl— "X-Bone CTL"; reference blank (no RFC in registry); assignee/contact Joe Touch; dual-registered 265/tcp + 265/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (rows 593–594); cross-checked against https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?page=6- Range class
- well-known (0–1023) [Confirmed]
- Prevalence / exposure
- nmap-services observed open-frequency 265/tcp ≈ 0.000013 — the dataset's lowest nonzero step [Confirmed] — nmap-services dataset; sibling 265/udp is 0 in the same dataset, i.e. no observed opens at all. Note that nmap labels the 265/tcp row
maybe-fw1— a community guess at Check Point FireWall-1, not an IANA registration, and not evidence for the unverified Check Point claim below. Beyond that figure, no documented honeypot activity or CVEs/exploits targeting 265/tcp were found [Unknown] - Related ports
- none identified as a documented cluster; no relation to SMTPS (465) despite the unverified claim above
Primary use
X-Bone control channel — a DARPA-funded automatic overlay-network (VPN-like) deployment/management research system built at USC/ISI by Joe Touch, active roughly late 1990s to early 2000s; not a currently deployed production protocol
Other/unofficial uses
no actively maintained software confirmed to implement x-bone-ctl today; a secondary, lower-authority source associates 265/tcp with Check Point FireWall-1/VPN-1's "Public Key Transfer Protocol," not corroborated by Check Point's own current documentation
Security implications
no known malware associations or vulnerabilities tied to this port; since X-Bone is a defunct research system, an unexpected open 265/tcp would be unusual and worth investigating rather than expected [Unknown]
Typically seen on
none identified in current production environments; historically, hosts running X-Bone research software (USC/ISI-affiliated) [Unknown]
- SMTPS claim
- a low-authority ports-listing site describes 265/tcp as "SMTP over SSL/TLS"; unverified and inconsistent with the conventional SMTPS port 465 — treat as unreliable [Unknown] — http://ports.my-addr.com/tcp_port-udp_port-application-and-description.php?port=265
- Analyst note
- A responsive 265/tcp is uncommon and not tied to any current mainstream service; verify context before assuming either the X-Bone research lineage or the unconfirmed Check Point/SMTPS claims.
About port 265/udp.
Port 265/udp is registered with IANA as x-bone-ctl, described simply as "X-Bone CTL," with Joe Touch listed as both assignee and contact; the entry is dual-registered on 265/tcp with identical fields, and the Registration Date, Modification Date, Reference, Service Code, and Unauthorized Use Reported columns are all blank in the registry — there is no RFC or other reference tied to this assignment. X-Bone was a DARPA-funded IP overlay-network research project run out of USC's Information Sciences Institute under Joe Touch, aimed at automating the deployment and management of virtual network topologies built from encapsulation tunnels over the existing Internet. In that architecture, Resource Daemons (RDs) running on participating hosts listened on this control port for request/response messages from a central Overlay Manager (OM), which used them to instantiate and tear down experimental overlay topologies. The project's final technical report (AFRL-IF-RS-TR-2003-182) was published in August 2003, and the reference RD/OM implementation appears in the XBone-3.2 codebase. No evidence surfaced of any current or production software using this port, and two independent port-lookup references (GRC and AuditMyPC) report no known trojan or malware association for 265/udp. Given the project's age and apparent dormancy, an analyst encountering unexpected traffic on this port today should treat it as anomalous rather than expected, since X-Bone deployments are not known to persist in modern networks.
- IANA assignment
x-bone-ctl— "X-Bone CTL"; reference blank (no RFC cited); assignee/contact Joe Touch; dual-registered 265/tcp + 265/udp with identical fields [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry, lines 593–594; cross-checked against https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml- Range class
- well-known / System Port (0–1023) [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
- Registration/modification date
- not present in the IANA registry row for this entry; not asserted [Unknown] — the IANA Service Name and Transport Protocol Port Number Registry
- Prevalence
- nmap-services lists
x-bone-ctlon 265/udp with an open-frequency of 0.000000 — catalogued, but never observed open in the dataset's scan sample, which matches the project's dormancy [Confirmed] — nmap-services dataset - Related ports
- 265/tcp — the same
x-bone-ctlregistration, dual-registered by IANA with an identical description ("X-Bone CTL") and the same assignee/contact Joe Touch; a service-name and assignee search of the cached registry returns these two rows and no others, so 265/tcp is the only port related to this one by registration (nmap-services labels the tcp sidemaybe-fw1, a community guess rather than an X-Bone sighting)[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry x-bone-ctl 265/tcp
Primary use
control port for X-Bone, a DARPA-funded IP overlay-network research project (USC ISI, led by Joe Touch); Resource Daemons listened for request/response control messages from the project's Overlay Manager to deploy/manage virtual encapsulation-tunnel topologies [Likely] — https://apps.dtic.mil/sti/pdfs/ADA418494.pdf (fetched via search-engine snippet after a direct-fetch 429; not a full-text direct read), corroborated by http://src.gnu-darwin.org/ports/net/xbone-gui/work/XBone-3.2/xbone/programs/XB_Params.pm.html
Other/unofficial uses
none identified beyond the X-Bone RD/OM reference software (XBone-3.2, early-2000s); no evidence of modern reuse
Security implications
no known trojan/malware association reported by two independent port-lookup databases; project is defunct/dormant, so unexpected traffic should be treated as anomalous [Confirmed for no-malware-association / Unknown for present-day exposure] — https://www.grc.com/port_265.htm, https://www.auditmypc.com/udp-port-265.asp
Typically seen on
no contemporary hosts identified; historically, USC ISI X-Bone research nodes running RD/OM software (early-to-mid 2000s)
Exposure/scanning notes
the nmap-services dataset, whose open-frequency column is derived from internet-wide scan sampling, carries x-bone-ctl on 265/udp at 0.000000 — the service is present in the catalogue but no host in the scan sample was recorded with this UDP port open. 265/tcp appears separately at 0.000013 (the dataset's lowest nonzero step) under the community label maybe-fw1, i.e. a suspected Check Point FireWall-1 port rather than X-Bone. A researched negative on the UDP side, not an unmeasured one
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| maybe-fw1 | TCP | x-bone-ctl | 0.00% |
| x-bone-ctl | UDP | X-Bone CTL | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.