Network port detail · TCP/UDP

268

Td-replica
Protocol(s)
TCP/UDP
Range
System (0-1023)

Summary

// if you see it open
No named trojan/malware family or CVE found for port 268 in standard bad-port reference lists (Trend Micro, Gary Kessler, Chebucto) as of this check; absence-of-evidence from a limited pass, not an exhaustive exposure survey (Shodan InternetDB excluded from this project's toolset on licensing grounds).
[ 01 ] — Context

About port 268/tcp.

Updated  ·  Confidence: Medium

Port 268/tcp is registered with IANA under the service name td-replica, described simply as "Tobit David Replica," with the identical name and description dual-registered on 268/udp. The registry lists Franz-Josef Leuders as both assignee and contact, and leaves the Reference field blank — no RFC underlies this entry, and none is invented here. IANA's registry gives no functional detail beyond the short label, but German-language administration documentation for Tobit Software's "David" server platform (a groupware/unified-communications product bundling email, fax, and voicemail, historically popular in German-speaking markets) consistently identifies port 268 as the replication port — often labeled "REPLIKA" — used to synchronize data between a David server and branch-office "replica" installations. Several of these third-party sources instruct administrators to forward the port through NAT for multi-site deployments to function correctly. Because this functional narrative comes from vendor/support pages rather than the IANA record itself, it is tagged Likely rather than Confirmed, and is kept clearly attributed as secondary. A scan of standard trojan/bad-port reference lists (Trend Micro's Trojan Ports list, Gary Kessler's Bad Ports list, Chebucto's trojan-port table) turned up no named malware family or CVE tied to port 268, though this is an absence-of-evidence result from a limited pass rather than an exhaustive exposure survey — Shodan InternetDB is excluded from this project's toolset on licensing grounds, so no live scan-count data was pulled. No registration or modification date is published by IANA for this legacy, assignee-style entry, so those fields stay null rather than fabricated, consistent with how this project treats unpublished registry dates.

IANA assignment
td-replica — "Tobit David Replica"; reference (blank — no RFC cited in IANA registry); assignee/contact Franz-Josef Leuders; dual-registered 268/tcp + 268/udp [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services observed open-frequency 268/tcp ≈ 0.00005 (very low — roughly 5 in 100,000 scanned hosts in the nmap-services sample); the dual-registered 268/udp side records 0.000000, catalogued but never observed open in that sample [Confirmed] — nmap-services dataset. The figure records scan-observed openness on the port number, not confirmed Tobit David replication traffic; live host counts (e.g. Shodan) were not pulled, as Shodan InternetDB is excluded from this project's toolset on licensing grounds [Unknown]
Related ports
Unknown — no other David-suite port associations verified in this pass [Unknown]
Registration/modification dates
Unknown — IANA publishes no date for this legacy assignee-style entry [Unknown]

Primary use

Tobit David groupware "REPLIKA" replication service, syncing data between a David server and remote/branch "replica" installations [Likely] — https://faq.kapa.de/content/6/372/de/welche-tcp_ip_ports-nutzt-tobit_david.html, https://www.fleutec.de/tobit-david-tcpip-ports/

Other/unofficial uses

administrators are instructed to forward this port through NAT for multi-site David replication to work

[Likely] — https://www.fleutec.de/tobit-david-tcpip-ports/, http://www.t1shopper.com/tools/port-number/268/

Security implications

no named trojan/malware family or CVE surfaced in standard bad-port reference lists checked (absence-of-evidence, not an exhaustive exposure survey; Shodan InternetDB excluded from this project's toolset on licensing grounds) [Likely] — https://docs.trendmicro.com/all/ent/officescan/v10.5/en-us/osce_10.5_olhcl/osce_topics/what_are_trojan_ports_.htm, https://www.garykessler.net/library/bad_ports.html, http://www.chebucto.ns.ca/~rakerman/trojan-port-table.html

Typically seen on

legacy/regional Tobit David groupware servers, primarily German-market installations performing multi-site replication

[Likely] — https://faq.kapa.de/content/6/372/de/welche-tcp_ip_ports-nutzt-tobit_david.html

Malware associations

none documented in the trojan/bad-port lists checked

[Likely] — https://www.garykessler.net/library/bad_ports.html
[ 02 ] — Context

About port 268/udp.

Updated  ·  Confidence: Medium

Port 268/udp is registered with IANA under the service name td-replica, described as "Tobit David Replica," with both assignee and contact listed as Franz Josef Leuders (IANA Service Name and Transport Protocol Port Number Registry). The Registration Date, Modification Date, and Reference/RFC columns are blank in the registry for this entry, and no RFC or other specification document is associated with the assignment — this reads as a legacy vendor-specific registration rather than an IETF-standardized protocol. Port 268/tcp carries an identical row in the same registry (same service name, description, assignee, and contact, with the same blank date/reference fields), so the assignment is dual-registered across both transports. The name points to Tobit Software's "David" product line — a German business-communication/groupware suite covering email, fax, and messaging — with "replica" suggesting a data-replication or synchronization role between David server instances, though the IANA entry itself carries no technical detail beyond the two-word label. Third-party port-lookup aggregators mirror the same IANA name and description without adding further protocol information. No CVEs, malware associations, honeypot or scan-telemetry reports, or documented internet-facing exposure were found for this port during research; it reads as a legacy, rarely-deployed vendor-specific port with no notable security history on record. Given the total absence of scanning or exploitation data, an analyst encountering traffic on 268/udp should treat it as either legitimate (but unlikely, given how obscure the vendor product is today) Tobit David replication traffic, or as an anomaly worth investigating on its own merits rather than against any known threat pattern.

IANA assignment
td-replica — "Tobit David Replica"; reference (blank — no RFC cited); assignee/contact Franz Josef Leuders; dual-registered 268/tcp + 268/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (live fetch) and local registry CSV cross-check (lines 599–600)
Range class
well-known (0–1023) [Confirmed]
Registration/modification dates
blank in the IANA registry for this entry — left null, not inferred [Confirmed] — IANA registry
Related ports
268/tcp — identical dual registration (same service name, description, assignee, blank reference) [Confirmed]

Primary use

data-replication component of Tobit Software's David groupware/messaging/fax server suite

[Likely] — IANA registry name/description only; no RFC or spec document exists to confirm protocol behavior

Other/unofficial uses

none documented

[Unknown] — no additional technical detail found on any port-lookup mirror

Security implications / exposure

no CVEs, malware associations, or scan-telemetry reports found; appears to be a legacy, rarely-deployed vendor-specific port

[Unknown] — searched SpeedGuide, my-addr.com, adminsub.net, MITRE ATT&CK, Exploit-DB (search date 2026-07-17)

Typically seen on

hosts running Tobit David software, if any remain in production; otherwise an anomaly [Likely]

// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
td-replica TCP Tobit David Replica 0.01%
td-replica UDP Tobit David Replica 0.00%
IANA name
td-replica
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.