35
Summary
- // if you see it open
- No CVEs or known exploits documented for 35/tcp specifically. SANS ISC records active scanning against the port; top sources at lookup time appeared as AWS-hosted IPs, consistent with automated low-port reconnaissance rather than targeted exploitation, and ISC listed the port's threat level as green (low concern). Legitimate 'private printer' use is largely obsolete (modern printing uses 515/LPD and 631/IPP); any open 35/tcp on a public host is anomalous and warrants investigation.
- // analyst note
- 35/tcp has no IANA service name and almost no legitimate modern use.
priv-printis a third-party label, not the IANA name. Don't infer a specific protocol from the port number — identify the listening process before drawing conclusions; modern printing lives on 515 and 631.
About port 35/tcp.
Port 35/tcp belongs to the same small family of well-known ports that are registered with IANA yet carry no service name. The canonical IANA Service Name and Transport Protocol Port Number Registry leaves the service-name field blank for both 35/tcp and 35/udp, lists the description "any private printer server," names the assignee and contact as Jon Postel (the editor responsible for the bulk of the early ARPANET-era assignments), and cites no RFC in the Reference column — there is no published registration or modification date for the row either. The intent was never a single specified protocol: port 35 was set aside as a catch-all so that proprietary or closed-network print servers could be reached without colliding with the standardized printing protocols that exist elsewhere — most notably the Line Printer Daemon on [port 515](/port/515) and the modern Internet Printing Protocol on [port 631](/port/631). Some third-party port databases and the SANS Internet Storm Center display the label priv-print for this port, but that name is a community convention rather than the IANA assignment, which is genuinely empty — exactly the situation on the neighboring "any private mail system" entry at [port 24](/port/24). In practice port 35 sees essentially no legitimate internet-facing traffic today; environments that print use IPP (631), LPD (515), or vendor-specific ports, so a host listening on 35/tcp on a public network is anomalous and worth a look. SANS ISC does record active scanning against the port, but with no standardized service expected there, that activity reads as automated reconnaissance sweeping the low ports rather than targeted exploitation of any port-35 protocol. No RFC, no CVE, and no canonical software are tied to 35/tcp specifically. For an analyst, treat an open 35/tcp as a rarely-legitimate port: identify the listening process and weigh a misconfigured private print service or a decoy/backdoor rather than inferring any specific protocol from the port number alone.
- IANA assignment
- service name blank (no name assigned) — description "any private printer server"; assignee/contact Jon Postel; reference blank (no RFC cited); no registration or modification date published; dual-registered 35/tcp + 35/udp with identical fields [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry lines 77–78; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)
- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- no meaningful legitimate internet-facing traffic today; not a high-frequency open port [Likely] — vendor/port-database commentary (no first-party scan frequency located; nmap-services figure not retrieved)
- Related ports
- 515 (LPD/printer), 631 (IPP/IPPS); contrast 24 (any private mail system) and the other blank-service-name private-* entries
Primary use
catch-all for proprietary / private printer servers; not a single specified protocol; distinct from standardized printing on 515 (LPD) and 631 (IPP)
Other/unofficial uses
third-party databases and SANS ISC label this port priv-print, a community convention not present in the IANA registry (the IANA service-name field is empty)
Security implications
no CVEs or known exploits documented for 35/tcp specifically. SANS ISC records active scanning against the port, with top sources at lookup time appearing as AWS-hosted IPs (consistent with automated low-port reconnaissance, not targeted exploitation); ISC listed the port's threat level as green (low concern). Because no legitimate service is widely expected here, any host found listening on 35/tcp in internet-wide scans is anomalous and warrants investigation
Typically seen on
legacy or proprietary private print services; otherwise an anomaly / possible backdoor or decoy
- Analyst note
- 35/tcp has no IANA service name and almost no legitimate modern use.
priv-printis a third-party label, not the IANA name. Don't infer a specific protocol from the port number — identify the listening process before drawing conclusions; modern printing lives on 515 and 631.
About port 35/udp.
Port 35/udp is registered with IANA as "any private printer server," with assignee Jon Postel and a blank reference field. It is one of a small cluster of early-ARPA-era "any private …" placeholders that Postel — the historic IANA custodian — set aside so vendors could run proprietary services on a well-known number without each needing its own formal assignment. The slot is dual-registered: 35/tcp carries the identical description "any private printer server" with the same assignee. No RFC is cited in the registry for this entry; the IANA Reference column is genuinely blank, not omitted. Because the assignment is a generic catch-all rather than a defined protocol, there is no canonical wire format, no named open-source daemon, and no widely deployed software documented as listening on 35/udp; the description reflects original intent (connectionless printer discovery or status signalling) rather than any standardized, deployed protocol. For an analyst, the port carries negligible documented internet exposure: no CVEs or public exploit disclosures are tied specifically to 35/udp, and it does not appear on commonly targeted port lists. Note that real-world printing-stack vulnerabilities in the literature (for example the CUPS family) target port 631, not port 35 — so an open 35/udp should be read as a vendor-private placeholder or anomaly, not as a known-exploitable printing service. UDP scanning (nmap -sU) of this port typically yields open|filtered because no active listener is expected and a missing listener is indistinguishable from a firewalled one.
- IANA assignment
- "any private printer server"; reference (blank — no RFC cited in IANA registry); assignee Jon Postel; dual-registered 35/tcp + 35/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 78; 35/tcp at line 77
- Range class
- well-known (0–1023) [Confirmed]
- Service name
- blank in registry (no short keyword assigned) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 78
- Registration / modification date
- Unknown — blank in the IANA registry; not fabricated [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 78
- Related ports
- the small "any private …" placeholder cluster; contrast modern printing on 631 (IPP/CUPS) and 515 (LPD)
Primary use
legacy "any private printer server" placeholder for vendor-proprietary printer discovery/status over UDP; no standardized protocol was ever defined for this slot
Common software
Unknown — no specific product is documented in IANA records or secondary port databases as using 35/udp; any usage would be proprietary and undisclosed
Security implications
negligible documented exposure; no CVEs or public exploits specific to 35/udp; printing-stack CVEs in the literature target port 631 (CUPS), not 35; UDP scan typically returns open|filtered
Typically seen on
not associated with any known deployed service; an open 35/udp is an anomaly / vendor-private placeholder
- Security risk level
- Low — legacy placeholder with no standardized protocol behind it; risk is limited to any coincidental proprietary implementation [Likely]
- Analyst note
- treat a responsive 35/udp as a proprietary vendor placeholder or anomaly to investigate, not a known-exploitable printing service.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| priv-print | UDP | any private printer server | 0.07% |
| priv-print | TCP | any private printer server | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.