283
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — rescap is an abandoned 1999 IETF draft that never became a standard or saw real-world implementation, so a service on 283/tcp is not a recognized production use and any listener should be treated as anomalous and investigated.
- // analyst note
- an open port 283 is not accounted for by any deployed standard protocol — investigate rather than assume legitimacy.
- // if you see it open
- rescap never achieved real-world deployment and has no RFC — the IANA Reference field is blank. A host answering on 283/tcp is more plausibly a non-standard/custom service, a honeypot, or coincidental port reuse than a genuine rescap server. No CVEs or malware associations found tied to this port; the negative check used search-result summaries only, not direct list fetches, so treat as lightly verified.
About port 283/tcp.
Port 283/tcp is registered with IANA under the service name rescap; the protocol behind it was never finished, never became an RFC, and has no legitimate reason to be open on an internet-facing host today.
IANA's Service Name and Transport Protocol Port Number Registry lists both 283/tcp and 283/udp as rescap, assignee and contact [Paul_Hoffman], with a blank Reference field — no RFC backs this port. The underlying spec is the expired IETF Internet-Draft draft-hoffman-rescap-protocol-01 (dated 1999-06-01), which describes "Resource Capabilities": a lightweight client-server lookup meant to resolve an identifier such as a mail address or URL into a list of capabilities before a client interacts with it. The draft explicitly reserves port 283 for a rescap server, with DNS SRV records allowed for alternate ports.
The draft expired without advancing to standards track, and no mainstream server, client, or library implementing rescap turned up in research — the protocol appears to have gone nowhere beyond the 1999 proposal. A host answering on 283/tcp today is far more plausibly a non-standard or custom service, a honeypot, or coincidental reuse of the port number than an actual rescap implementation.
Port 283 does not appear on the common trojan/backdoor port references checked during research, though that check relied on search-result summaries rather than a line-by-line read of each list, so the negative should be treated as lightly verified rather than definitive.
- IANA assignment
rescap— description "rescap" (CSV Description field is identical to Service Name for this entry, not a transcription error); reference blank; assignee/contact[Paul_Hoffman]; dual-registered 283/tcp + 283/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Registration/modification dates
- both blank in the IANA CSV for this entry — left null, not fabricated [Confirmed]
- Prevalence
- not assessed in this pass; no telemetry source (e.g. nmap-services) consulted [Unknown]
- Related ports
- none identified as directly related
Primary use
proposed "Resource Capabilities" resolution protocol per expired IETF Internet-Draft draft-hoffman-rescap-protocol-01 (1999-06-01); never advanced to RFC
Other/unofficial uses
none found; no known software implements rescap [Unknown]
Security implications
anomalous if seen open; no CVEs or malware associations found tied to this port; negative check against trojan-port lists was via search summaries only, not direct source fetches [Likely]
Typically seen on
no known production hosts; a decoy, custom service, or coincidental port reuse is more plausible than a genuine rescap server [Likely]
- Analyst note
- an open port 283 is not accounted for by any deployed standard protocol — investigate rather than assume legitimacy.
About port 283/udp.
Port 283/udp is registered to rescap, an IETF Applications-Area protocol for resolving a resource identifier into a list of capability attributes; the protocol never became an RFC and shows no evidence of real-world deployment, so traffic on it today should be treated as anomalous rather than as legitimate rescap service activity.
The IANA Service Name and Transport Protocol Port Number Registry lists port 283 as rescap on both tcp and udp, assigned to Paul Hoffman, with the Reference, Registration Date, Modification Date, and Service Code fields all blank. No RFC number is cited for this assignment.
RESCAP itself dates to an IETF working group active around 1999–2000 (now concluded). Its Internet-Drafts — including draft-hoffman-rescap-protocol, draft-ietf-rescap-proto-main, draft-ietf-rescap-proto-format, draft-ietf-rescap-rc, and draft-ietf-rescap-scenarios — specified a server listening identically on TCP and UDP port 283, using UDP for small requests and falling back to TCP when a response exceeded 512 octets. All of these drafts expired without progressing to standards-track status.
No shipping client or server software implementing RESCAP has been identified, and the port does not appear on the trojan/backdoor port lists checked (Trend Micro's Trojan Ports reference and garykessler.net's Bad Ports list). No live scan or threat-intelligence telemetry was consulted for this pass, since AbuseIPDB and Shodan InternetDB are commercial-use prohibited for this site and out of scope for a registry-focused research pass.
- IANA assignment
rescap(udp and tcp), description "rescap"; assignee [Paul_Hoffman]; Reference/Registration Date/Modification Date/Service Code fields blank in the registry [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml- Range class
- well-known (0–1023) [Confirmed]
- Dual registration
- 283/tcp is also registered to
rescapunder the same assignee [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry, lines 614–615 - Prevalence
- not assessed in this pass (no scan telemetry consulted; AbuseIPDB/Shodan InternetDB licensing-prohibited for this site) [Unknown]
- Related ports
- 283/tcp (same rescap dual registration) [Confirmed]
Primary use
RESCAP Resolution Protocol — resolves a resource identifier (e.g., a mail recipient) into a list of capability attributes; server runs on TCP and UDP port 283 identically, UDP preferred for small requests, TCP required when the response exceeds 512 octets
Other/unofficial uses
none identified; no shipping software implementation found [Unknown]
Security implications
no known legitimate deployment; not listed on the trojan/backdoor port lists checked (Trend Micro, garykessler.net) [Likely] — https://www.garykessler.net/library/bad_ports.html, https://docs.trendmicro.com/all/ent/officescan/v10.5/en-us/osce_10.5_olhcl/osce_topics/what_are_trojan_ports_.htm
Typically seen on
no known population of hosts running this service; an open port would be anomalous [Unknown]
- RFC status
- never published as an RFC; all RESCAP-family Internet-Drafts expired; IETF working group status is Concluded [Confirmed] — https://datatracker.ietf.org/wg/rescap/about/, https://datatracker.ietf.org/doc/html/draft-hoffman-rescap-protocol-01
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| rescap | TCP | — | 0.00% |
| rescap | UDP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.