Network port detail · TCP/UDP

283

Rescap
Protocol(s)
TCP/UDP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — rescap is an abandoned 1999 IETF draft that never became a standard or saw real-world implementation, so a service on 283/tcp is not a recognized production use and any listener should be treated as anomalous and investigated.
// analyst note
an open port 283 is not accounted for by any deployed standard protocol — investigate rather than assume legitimacy.
// if you see it open
rescap never achieved real-world deployment and has no RFC — the IANA Reference field is blank. A host answering on 283/tcp is more plausibly a non-standard/custom service, a honeypot, or coincidental port reuse than a genuine rescap server. No CVEs or malware associations found tied to this port; the negative check used search-result summaries only, not direct list fetches, so treat as lightly verified.
[ 01 ] — Context

About port 283/tcp.

Updated  ·  Confidence: Medium

Port 283/tcp is registered with IANA under the service name rescap; the protocol behind it was never finished, never became an RFC, and has no legitimate reason to be open on an internet-facing host today.

IANA's Service Name and Transport Protocol Port Number Registry lists both 283/tcp and 283/udp as rescap, assignee and contact [Paul_Hoffman], with a blank Reference field — no RFC backs this port. The underlying spec is the expired IETF Internet-Draft draft-hoffman-rescap-protocol-01 (dated 1999-06-01), which describes "Resource Capabilities": a lightweight client-server lookup meant to resolve an identifier such as a mail address or URL into a list of capabilities before a client interacts with it. The draft explicitly reserves port 283 for a rescap server, with DNS SRV records allowed for alternate ports.

The draft expired without advancing to standards track, and no mainstream server, client, or library implementing rescap turned up in research — the protocol appears to have gone nowhere beyond the 1999 proposal. A host answering on 283/tcp today is far more plausibly a non-standard or custom service, a honeypot, or coincidental reuse of the port number than an actual rescap implementation.

Port 283 does not appear on the common trojan/backdoor port references checked during research, though that check relied on search-result summaries rather than a line-by-line read of each list, so the negative should be treated as lightly verified rather than definitive.

IANA assignment
rescap — description "rescap" (CSV Description field is identical to Service Name for this entry, not a transcription error); reference blank; assignee/contact [Paul_Hoffman]; dual-registered 283/tcp + 283/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Registration/modification dates
both blank in the IANA CSV for this entry — left null, not fabricated [Confirmed]
Prevalence
not assessed in this pass; no telemetry source (e.g. nmap-services) consulted [Unknown]
Related ports
none identified as directly related

Primary use

proposed "Resource Capabilities" resolution protocol per expired IETF Internet-Draft draft-hoffman-rescap-protocol-01 (1999-06-01); never advanced to RFC

[Confirmed] — IETF Internet-Draft draft-hoffman-rescap-protocol-01

Other/unofficial uses

none found; no known software implements rescap [Unknown]

Security implications

anomalous if seen open; no CVEs or malware associations found tied to this port; negative check against trojan-port lists was via search summaries only, not direct source fetches [Likely]

Typically seen on

no known production hosts; a decoy, custom service, or coincidental port reuse is more plausible than a genuine rescap server [Likely]

Analyst note
an open port 283 is not accounted for by any deployed standard protocol — investigate rather than assume legitimacy.
[ 02 ] — Context

About port 283/udp.

Updated  ·  Confidence: Medium

Port 283/udp is registered to rescap, an IETF Applications-Area protocol for resolving a resource identifier into a list of capability attributes; the protocol never became an RFC and shows no evidence of real-world deployment, so traffic on it today should be treated as anomalous rather than as legitimate rescap service activity.

The IANA Service Name and Transport Protocol Port Number Registry lists port 283 as rescap on both tcp and udp, assigned to Paul Hoffman, with the Reference, Registration Date, Modification Date, and Service Code fields all blank. No RFC number is cited for this assignment.

RESCAP itself dates to an IETF working group active around 1999–2000 (now concluded). Its Internet-Drafts — including draft-hoffman-rescap-protocol, draft-ietf-rescap-proto-main, draft-ietf-rescap-proto-format, draft-ietf-rescap-rc, and draft-ietf-rescap-scenarios — specified a server listening identically on TCP and UDP port 283, using UDP for small requests and falling back to TCP when a response exceeded 512 octets. All of these drafts expired without progressing to standards-track status.

No shipping client or server software implementing RESCAP has been identified, and the port does not appear on the trojan/backdoor port lists checked (Trend Micro's Trojan Ports reference and garykessler.net's Bad Ports list). No live scan or threat-intelligence telemetry was consulted for this pass, since AbuseIPDB and Shodan InternetDB are commercial-use prohibited for this site and out of scope for a registry-focused research pass.

IANA assignment
rescap (udp and tcp), description "rescap"; assignee [Paul_Hoffman]; Reference/Registration Date/Modification Date/Service Code fields blank in the registry [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Range class
well-known (0–1023) [Confirmed]
Dual registration
283/tcp is also registered to rescap under the same assignee [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry, lines 614–615
Prevalence
not assessed in this pass (no scan telemetry consulted; AbuseIPDB/Shodan InternetDB licensing-prohibited for this site) [Unknown]
Related ports
283/tcp (same rescap dual registration) [Confirmed]

Primary use

RESCAP Resolution Protocol — resolves a resource identifier (e.g., a mail recipient) into a list of capability attributes; server runs on TCP and UDP port 283 identically, UDP preferred for small requests, TCP required when the response exceeds 512 octets

[Confirmed] — https://datatracker.ietf.org/wg/rescap/about/, https://www.ietf.org/archive/id/draft-hoffman-rescap-protocol-01.txt

Other/unofficial uses

none identified; no shipping software implementation found [Unknown]

Security implications

no known legitimate deployment; not listed on the trojan/backdoor port lists checked (Trend Micro, garykessler.net) [Likely] — https://www.garykessler.net/library/bad_ports.html, https://docs.trendmicro.com/all/ent/officescan/v10.5/en-us/osce_10.5_olhcl/osce_topics/what_are_trojan_ports_.htm

Typically seen on

no known population of hosts running this service; an open port would be anomalous [Unknown]

RFC status
never published as an RFC; all RESCAP-family Internet-Drafts expired; IETF working group status is Concluded [Confirmed] — https://datatracker.ietf.org/wg/rescap/about/, https://datatracker.ietf.org/doc/html/draft-hoffman-rescap-protocol-01
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
rescap TCP 0.00%
rescap UDP 0.00%
IANA name
rescap
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.