317
Summary
- // if you see it open
- No documented CVE, malware association, or notable scanning signal was found for 317/tcp. The IANA record and its contact address at a 1990s-era U.S. ISP domain suggest a legacy, likely-dormant registration rather than an actively deployed service. An unexpected open port 317 should be treated as unidentified and investigated rather than assumed benign, since no legitimate designed use is documented. Note: Wikipedia's port-number list misattributes port 317 to PKIX Time Stamp Protocol (TSP); that assignment actually belongs to port 318 (pkix-timestamp) per the IANA registry.
- // analyst note
- Wikipedia's port-number list article mislabels 317 as PKIX Time Stamp Protocol; that assignment belongs to port 318. Treat 317/tcp as an obscure, undocumented legacy IANA registration with no known real-world footprint.
About port 317/tcp.
Port 317/tcp is registered with IANA under the service name zannet, but no protocol specification, implementing software, or documented real-world usage has been identified anywhere in this research pass; whether the port belongs on the public internet is therefore genuinely unknown rather than a confirmed safe or unsafe assignment.
The IANA Service Name and Transport Protocol Port Number Registry lists 317/tcp (and the matching 317/udp) as zannet, description "Zannet," assignee Zan Oliphant, with a registry contact address at a 1990s-era U.S. ISP domain. The registry's Registration Date and Reference/RFC fields are both blank for this entry, which is typical of pre-2000s IANA registrations and is recorded here as a genuine absence rather than an omission.
No RFC, vendor documentation, or software product implementing "zannet" could be found. No entry for 317/tcp appears in major port-scanning writeups, Shodan/Censys prioritized-port discussions, or vulnerability databases (NVD/CVE) surfaced in this pass, suggesting negligible real-world exposure — though this is an absence-of-evidence finding, not a confirmed clean bill of health.
One correction worth noting: Wikipedia's "List of TCP and UDP port numbers" article currently mislabels port 317 as "PKIX Time Stamp Protocol (TSP)." That assignment actually belongs to port 318 (pkix-timestamp, assignee Robert Zuccherato), confirmed directly against the IANA CSV. IANA was treated as authoritative and the Wikipedia claim was rejected for this entry.
- IANA assignment
zannet— "Zannet"; reference (blank — no RFC cited in IANA registry); assignee Zan Oliphant [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Dual registration
- 317/tcp + 317/udp both assigned identically to zannet [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-646
- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- No scanning/prevalence data found in this pass; not observed in Shodan/Censys prioritized-port discussions or major port-scanning writeups [Unknown]
- Related ports
- 318/tcp+udp (
pkix-timestamp) — the correct PKIX TimeStamp assignment, commonly confused with 317 due to a Wikipedia error [Confirmed] — IANA registry
Primary use
Unknown/undocumented — no protocol specification, RFC, or vendor documentation found describing what zannet does
Other/unofficial uses
None identified [Unknown]
Security implications
No documented CVE, malware association, or notable scanning signal found for 317/tcp; legacy registrant contact suggests a likely-dormant assignment rather than an active service
Typically seen on
Unknown — no implementing software or deployment pattern identified [Unknown]
- Analyst note
- Wikipedia's port-number list article mislabels 317 as PKIX Time Stamp Protocol; that assignment belongs to port 318. Treat 317/tcp as an obscure, undocumented legacy IANA registration with no known real-world footprint.
About port 317/udp.
Port 317/udp is IANA-registered under the service name zannet, assigned to Zan Oliphant, but the registry gives no functional description beyond the name itself — no RFC reference, no registration date, and no explanation of what the protocol does. Because of that gap, whether traffic on this port belongs on the public internet cannot be answered with confidence; it should be treated as unverified and kept off internet-facing interfaces unless a specific deployment can justify otherwise.
The same zannet name and blank metadata appear on the paired TCP registration (317/tcp), confirming this was registered as a dual TCP/UDP service rather than being UDP-specific. This dual-protocol pattern is common in the early IANA port-registry era, when individuals could reserve a name across both transports for a planned protocol that may never have shipped widely.
No corroborating documentation was found in vendor references, common port-database aggregators, or scanning/threat-intelligence sources describing an active zannet implementation, nor any record of it appearing on mass-scan target lists or in CVE data. That absence of evidence is not the same as a confirmed-safe verdict — it reflects a lack of public documentation rather than a security assessment, so an analyst who finds this port open should investigate the host rather than assume a benign default.
- IANA assignment
zannet— description "Zannet"; reference (blank); assignee/contact [Zan_Oliphant]; dual-registered 317/tcp + 317/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry; IANA registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- not assessed in this research pass [Unknown]
- Related ports
- 317/tcp (identical zannet dual registration)
Primary use
Unknown — no functional description in the IANA registry beyond the service name; no corroborating vendor/software documentation found
Other/unofficial uses
none identified [Unknown]
Security implications
obscure/legacy individual registration with no public documentation; no evidence of scanning or exploitation activity found in this pass, but that is absence-of-evidence, not confirmed-safe [Likely] — IANA registry; web search (third-party port-database sites returned 403/cert errors and could not be independently corroborated)
Typically seen on
unknown/unverified
- Analyst note
- The IANA description field literally reads "Zannet" with no further explanation on file — treat this as a sparse legacy registration, not a documented protocol.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| zannet | UDP | — | 0.03% |
| zannet | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.