349
Summary
- // if you see it open
- No known CVEs, advisories, or malware associations found for port 349. Because it is registered but almost never observed live, any traffic seen on 349/tcp should be treated as atypical and investigated case-by-case rather than attributed to a known service or threat family by default.
- // analyst note
- Blank IANA Reference and Registration Date fields are a legitimate registry gap for this entry, not a data-collection failure — do not infer a date or RFC that isn't cited.
About port 349/tcp.
Port 349/tcp is IANA-registered under the service name mftp, but the registry provides only the bare name and an assignee (Dave Feinleib) with no description, RFC reference, or protocol specification — so what actually runs here, and whether it belongs on the public internet, cannot be confirmed. Any traffic observed on this port should be treated as unusual rather than assumed to belong to a known, well-documented service.
The IANA Reference and Registration Date columns are blank in the authoritative registry. That is a legitimate gap rather than missing data: some early service-name registrations predate the practice of citing a defining RFC or a registration date, and mftp appears to be one of them. The port is dual-registered, with a matching 349/udp entry under the same name and assignee.
No vendor documentation, forum thread, or community sighting could be found describing what software actually generates traffic on 349/tcp, despite a dedicated research pass this cycle. nmap's scan-derived service-frequency data places the port at essentially zero observed frequency on TCP (and near-zero on UDP), consistent with a registered-but-dormant assignment rather than an actively deployed service.
Because neither the protocol nor its typical software is documented, this entry carries mostly Unknown fields tagged honestly rather than guessed. An analyst who sees live traffic on 349/tcp should treat it as noteworthy precisely because it has no established baseline — investigate it rather than assume it maps to mftp or any specific application.
- IANA assignment
mftp— bare service name, no description text; reference (blank — none cited in the registry); assignee/contact Dave Feinleib; dual-registered 349/tcp + 349/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence
- nmap-services observed-frequency 349/tcp ≈ 0.000000; 349/udp ≈ 0.000297 [Likely] — nmap-services file (svn.nmap.org/nmap/nmap-services)
- Related ports
- 349/udp (same
mftpregistration, dual-registered pair)
Primary use
Unknown — IANA registry gives only the name mftp with no defining RFC or description; no authoritative protocol spec could be located [Unknown]
Other/unofficial uses
none confirmed — no vendor docs or community sightings surfaced this cycle [Unknown]
Security implications
no known CVEs or advisories reference this port; given near-zero real-world observation, any activity here is atypical and merits investigation rather than assumption of a known service [Unknown/Likely]
Typically seen on
no confirmed host/software population; registered-but-effectively-unused assignment [Unknown]
- Analyst note
- Blank IANA Reference and Registration Date fields are a legitimate registry gap for this entry, not a data-collection failure — do not infer a date or RFC that isn't cited.
About port 349/udp.
Port 349/udp is registered with IANA under the service name mftp, but no RFC or protocol specification backs the registration, so what actually runs on the port in practice is unknown — it should not be assumed safe for public-internet exposure, and any observed traffic on it warrants investigation rather than routine trust.
The IANA registry lists 349 as dual-registered on both TCP and UDP under the name mftp, description "mftp," with assignee Dave Feinleib and a blank Reference field. No linked RFC, draft, or specification document is cited, and the registry provides no further protocol detail beyond the bare name.
A secondary source (SANS Internet Storm Center) has informally expanded "mftp" as "Maple File Transfer Protocol," but this expansion could not be independently corroborated from an authoritative source such as an RFC, vendor spec, or the IANA record itself, so it is recorded here as unverified rather than fact.
Observed traffic data is thin: SANS ISC's port page shows routine internet-wide background scanning hitting port 349, consistent with generic mass-scanner probing seen across most registered ports rather than any targeted or malware-specific pattern. No CVE and no malware/trojan association were found for this port.
- IANA assignment
mftp— description "mftp"; reference field blank; assignee Dave_Feinleib; dual-registered 349/tcp + 349/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence
- Unknown — no nmap-services frequency or telemetry data located for this port in research [Unknown]
- Related ports
- none identified in research
Primary use
Unknown — IANA registers only the name mftp with no RFC or protocol description on file
Other/unofficial uses
unverified secondary claim of "Maple File Transfer Protocol" (not independently corroborated)
Security implications
no CVE or malware association found; SANS ISC shows routine internet-wide background scanning consistent with generic mass-scanner probing across most registered ports
Typically seen on
Unknown — no confirmed deployments or vendor documentation identified [Unknown]
- Analyst note
- A thinly-documented registered service with no protocol spec and no verified legitimate deployment — any traffic on 349/udp should be treated as worth investigating rather than assumed benign.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| mftp | UDP | — | 0.03% |
| mftp | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.