Network port detail · UDP/TCP

370

Codaauth2
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Internal-only — codaauth2 authenticates Coda distributed-filesystem clients against Coda servers on a trusted network and is not designed or documented as a public-internet-facing service.
// common applications
Coda distributed filesystem (venus clienCoda auth2 server (codasrv/auth2) Traffic on this port is most often Coda distributed-filesystem authentication; Coda's venus client and auth2 server have been reported using it to exchange authentication tokens, with no other mainstream software documented on this port.
// analyst note
Coda and codaauth2 are a legacy academic protocol with very limited modern deployment; an open port 370 is uncommon and worth confirming as a genuine Coda service rather than assuming it is benign.
// if you see it open
No CVEs or malware families specifically tied to port 370/codaauth2 were found. Coda is a legacy/niche academic distributed filesystem with limited modern deployment, so public exposure is plausibly rare, though this is unverified against live scan/telemetry data (e.g. Shodan/Censys).
[ 01 ] — Context

About port 370/tcp.

Updated  ·  Confidence: Medium

Port 370/tcp carries codaauth2, the authentication service for the Coda distributed filesystem; it is a niche, legacy academic protocol that belongs on trusted/internal networks rather than exposed to the public internet.

IANA's registry lists 370 as dual-registered on TCP and UDP under the service name codaauth2, description "codaauth2," assignee Robert Watson, with a blank Reference field — meaning no RFC is cited for the assignment.

Coda is a distributed filesystem that originated as a Carnegie Mellon University research project, commonly dated to 1987 and associated with Mahadev Satyanarayanan; this origin detail could not be directly confirmed against coda.cs.cmu.edu during this research pass, so it is treated as likely rather than confirmed. The codaauth2 service handles authentication and token issuance between Coda clients (the venus client) and Coda authentication servers, letting a client obtain credentials before mounting or accessing Coda volumes.

No scan-prevalence statistics (such as Shodan or Censys counts) or dated exposure studies for port 370 were found in this pass, and no CVEs or malware families are documented as tied to this port or to codaauth2 specifically. Given Coda's status as a legacy, low-adoption academic filesystem, a responsive port 370 today is more likely a research or legacy deployment than mainstream infrastructure.

IANA assignment
codaauth2 — "codaauth2"; reference (blank); assignee Robert Watson; dual-registered 370/tcp + 370/udp [Confirmed] — IANA service-names-port-numbers registry
Range class
well-known (0–1023) [Confirmed]
Prevalence
Unknown — no nmap-services open-frequency or scan-prevalence data found in this pass
Related ports
none documented as part of a Coda-specific port cluster in this pass [Unknown]

Primary use

authentication/token-issuance service for the Coda distributed filesystem, between Coda clients (venus) and Coda auth2 servers

[Likely] — Wikipedia List of TCP and UDP port numbers

Other/unofficial uses

none documented in this pass [Unknown]

Security implications

no CVEs or malware families tied to port 370/codaauth2 documented; Coda's legacy/niche status makes broad public exposure plausible but unverified [Unknown]

Typically seen on

legacy or research Coda distributed-filesystem deployments (client venus + auth2 server) [Likely]

Analyst note
Coda and codaauth2 are a legacy academic protocol with very limited modern deployment; an open port 370 is uncommon and worth confirming as a genuine Coda service rather than assuming it is benign.
[ 02 ] — Context

About port 370/udp.

Updated  ·  Confidence: Medium

Port 370/udp carries codaauth2, the authentication-server component of the Coda distributed file system, and it should remain internal-only rather than exposed to the public internet.

IANA's Service Name and Transport Protocol Port Number Registry confirms codaauth2 as the registered name for both 370/tcp and 370/udp, with assignee and contact Robert Watson and no RFC or reference document cited. Coda is a distributed file system, first developed as a research project at Carnegie Mellon University beginning in 1987, that supports disconnected operation and server replication; codaauth2 is version 2 of its Kerberos-derived authentication protocol.

Real-world visibility is minimal. Nmap's nmap-services frequency data lists 370/udp at roughly 0.001038 (about 0.1%) and 370/tcp at about 0.000013 among scanned open ports — negligible rates indicating this is not a commonly open or commonly targeted service today. No independent blog, forum, or vendor-documentation sighting of other software using this port was found, so the only credible traffic source identified is Coda's own auth2 daemon.

IANA assignment
codaauth2 — description "codaauth2"; dual-registered 370/tcp and 370/udp; assignee/contact Robert Watson; reference field blank [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry, https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml. Commonly interpreted as the Coda distributed file system's "auth2" authentication server
[Likely] — https://en.wikipedia.org/wiki/Coda_(file_system)
Range class
well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Prevalence
nmap-services open-frequency 370/udp ≈ 0.001038 (~0.1%); 370/tcp ≈ 0.000013 [Confirmed] — https://svn.nmap.org/nmap/nmap-services
Related ports
370/tcp (dual registration, same codaauth2 service) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-734

Primary use

authentication server (auth2) for the Coda distributed file system's Kerberos-derived authentication protocol, version 2

[Likely] — https://en.wikipedia.org/wiki/Coda_(file_system)

Other/unofficial uses

none identified in this research pass [Unknown]

Security implications

internal-only authentication service, never legitimately public-facing; malware/trojan association unverifiable this session (SpeedGuide returned HTTP 403)

[Confirmed/Unknown] — https://svn.nmap.org/nmap/nmap-services

Typically seen on

legacy or niche Coda distributed-file-system deployments

[Likely] — https://en.wikipedia.org/wiki/Coda_(file_system)
Analyst note
An open 370/udp is statistically rare; if seen, it most likely indicates an active Coda file-system deployment rather than a common service — verify context before assuming malicious intent.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
codaauth2 UDP 0.10%
codaauth2 TCP 0.00%
IANA name
codaauth2
Transport
TCP AND UDP (DUAL REGISTRATION)
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.