370
Summary
- // typical exposure
- Internal-only — codaauth2 authenticates Coda distributed-filesystem clients against Coda servers on a trusted network and is not designed or documented as a public-internet-facing service.
- // common applications
- Coda distributed filesystem (venus clienCoda auth2 server (codasrv/auth2) Traffic on this port is most often Coda distributed-filesystem authentication; Coda's venus client and auth2 server have been reported using it to exchange authentication tokens, with no other mainstream software documented on this port.
- // analyst note
- Coda and codaauth2 are a legacy academic protocol with very limited modern deployment; an open port 370 is uncommon and worth confirming as a genuine Coda service rather than assuming it is benign.
- // if you see it open
- No CVEs or malware families specifically tied to port 370/codaauth2 were found. Coda is a legacy/niche academic distributed filesystem with limited modern deployment, so public exposure is plausibly rare, though this is unverified against live scan/telemetry data (e.g. Shodan/Censys).
About port 370/tcp.
Port 370/tcp carries codaauth2, the authentication service for the Coda distributed filesystem; it is a niche, legacy academic protocol that belongs on trusted/internal networks rather than exposed to the public internet.
IANA's registry lists 370 as dual-registered on TCP and UDP under the service name codaauth2, description "codaauth2," assignee Robert Watson, with a blank Reference field — meaning no RFC is cited for the assignment.
Coda is a distributed filesystem that originated as a Carnegie Mellon University research project, commonly dated to 1987 and associated with Mahadev Satyanarayanan; this origin detail could not be directly confirmed against coda.cs.cmu.edu during this research pass, so it is treated as likely rather than confirmed. The codaauth2 service handles authentication and token issuance between Coda clients (the venus client) and Coda authentication servers, letting a client obtain credentials before mounting or accessing Coda volumes.
No scan-prevalence statistics (such as Shodan or Censys counts) or dated exposure studies for port 370 were found in this pass, and no CVEs or malware families are documented as tied to this port or to codaauth2 specifically. Given Coda's status as a legacy, low-adoption academic filesystem, a responsive port 370 today is more likely a research or legacy deployment than mainstream infrastructure.
- IANA assignment
codaauth2— "codaauth2"; reference (blank); assignee Robert Watson; dual-registered 370/tcp + 370/udp [Confirmed] — IANA service-names-port-numbers registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- Unknown — no nmap-services open-frequency or scan-prevalence data found in this pass
- Related ports
- none documented as part of a Coda-specific port cluster in this pass [Unknown]
Primary use
authentication/token-issuance service for the Coda distributed filesystem, between Coda clients (venus) and Coda auth2 servers
Other/unofficial uses
none documented in this pass [Unknown]
Security implications
no CVEs or malware families tied to port 370/codaauth2 documented; Coda's legacy/niche status makes broad public exposure plausible but unverified [Unknown]
Typically seen on
legacy or research Coda distributed-filesystem deployments (client venus + auth2 server) [Likely]
- Analyst note
- Coda and codaauth2 are a legacy academic protocol with very limited modern deployment; an open port 370 is uncommon and worth confirming as a genuine Coda service rather than assuming it is benign.
About port 370/udp.
Port 370/udp carries codaauth2, the authentication-server component of the Coda distributed file system, and it should remain internal-only rather than exposed to the public internet.
IANA's Service Name and Transport Protocol Port Number Registry confirms codaauth2 as the registered name for both 370/tcp and 370/udp, with assignee and contact Robert Watson and no RFC or reference document cited. Coda is a distributed file system, first developed as a research project at Carnegie Mellon University beginning in 1987, that supports disconnected operation and server replication; codaauth2 is version 2 of its Kerberos-derived authentication protocol.
Real-world visibility is minimal. Nmap's nmap-services frequency data lists 370/udp at roughly 0.001038 (about 0.1%) and 370/tcp at about 0.000013 among scanned open ports — negligible rates indicating this is not a commonly open or commonly targeted service today. No independent blog, forum, or vendor-documentation sighting of other software using this port was found, so the only credible traffic source identified is Coda's own auth2 daemon.
- IANA assignment
codaauth2— description "codaauth2"; dual-registered 370/tcp and 370/udp; assignee/contact Robert Watson; reference field blank [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry, https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml. Commonly interpreted as the Coda distributed file system's "auth2" authentication server[Likely] — https://en.wikipedia.org/wiki/Coda_(file_system)- Range class
- well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
- Prevalence
- nmap-services open-frequency 370/udp ≈ 0.001038 (~0.1%); 370/tcp ≈ 0.000013 [Confirmed] — https://svn.nmap.org/nmap/nmap-services
- Related ports
- 370/tcp (dual registration, same codaauth2 service) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry-734
Primary use
authentication server (auth2) for the Coda distributed file system's Kerberos-derived authentication protocol, version 2
Other/unofficial uses
none identified in this research pass [Unknown]
Security implications
internal-only authentication service, never legitimately public-facing; malware/trojan association unverifiable this session (SpeedGuide returned HTTP 403)
Typically seen on
legacy or niche Coda distributed-file-system deployments
- Analyst note
- An open 370/udp is statistically rare; if seen, it most likely indicates an active Coda file-system deployment rather than a common service — verify context before assuming malicious intent.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| codaauth2 | UDP | — | 0.10% |
| codaauth2 | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.