Network port detail · UDP/TCP

403

Decap
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — No legitimate protocol or software is documented as using 403/tcp; the bare 'decap' IANA entry has no deployed service, so a responsive port 403 is atypical and warrants investigation rather than being treated as routine service traffic.
// analyst note
Port 403/tcp has no documented legitimate service; treat any activity here as anomalous and worth investigating rather than routine.
// if you see it open
No CVE or malware family is confirmed to be associated with 403/tcp. A 2000-era SecLists incidents thread discusses unexplained/anomalous traffic on the port under the 'decap?' name. SANS Internet Storm Center tracks per-port attack activity for 403 among its scanned-port dashboards, but volumes/trends could not be verified. Because no legitimate application is documented, an open or probed port 403 should be treated as atypical.
[ 01 ] — Context

About port 403/tcp.

Updated  ·  Confidence: Low

Port 403/tcp carries no documented, actively used protocol; IANA lists it only under the bare service name "decap" with no assignee and no reference, so it should be treated as an unused or anomalous port rather than one appropriate to expose to the public internet.

IANA's Service Name and Transport Protocol Port Number Registry assigns 403 to "decap" on both TCP and UDP, a legacy entry with blank Assignee and Reference fields. The name is widely believed, though not confirmed by any RFC, to abbreviate "decapsulation." The entry appears to date from the RFC 1700-era registry consolidation of 1994 rather than from a maintained specification.

No modern client or server software could be confirmed as using this port. Searches surfaced only generic port-lookup directory mirrors (speedguide.net and similar sites) that restate the bare IANA line without documenting any real deployment, vendor product, or protocol behavior tied to port 403.

A 2000-era SecLists incidents thread discusses unexplained, anomalous traffic observed on TCP port 403 under the "decap?" name, and SANS Internet Storm Center maintains a per-port attack-activity tracking page for 403, indicating it appears among the long tail of ports monitored for scanning activity — though specific volumes or trends could not be verified.

IANA assignment
decap — no description beyond the bare service name; assignee blank; reference blank (no RFC cited); dual-registered 403/tcp + 403/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (line 799); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services open-frequency for 403/tcp ≈ 0.000025 [Confirmed] — this site's own tooling
Related ports
none specifically documented as related [Unknown]

Primary use

none confirmed/deployed; legacy IANA name "decap" (believed to mean "decapsulation," unconfirmed), an RFC 1700-era (1994) entry with no dedicated specification

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Other/unofficial uses

none credibly documented; only generic port-directory mirror sites restate the bare IANA entry

[Unknown] — https://www.speedguide.net/port.php?port=403

Security implications

no confirmed CVE or malware family; a 2000-era SecLists thread reports unexplained/anomalous traffic under the "decap?" name; SANS ISC tracks the port on its per-port attack-activity dashboard (content/volumes unverified)

[Threat-reported/Unknown] — https://seclists.org/incidents/2000/Oct/84, https://isc.sans.edu/data/port/403

Typically seen on

no confirmed legitimate deployment; a responsive port 403 is atypical and should be investigated as anomalous or probed traffic [Unknown]

Analyst note
Port 403/tcp has no documented legitimate service; treat any activity here as anomalous and worth investigating rather than routine.
[ 02 ] — Context

About port 403/udp.

Updated  ·  Confidence: Medium

Port 403/udp is registered with IANA under the name decap, but no protocol specification, vendor documentation, or widely-used software has been confirmed to run on it, so a responsive 403/udp should be treated as anomalous rather than expected internet-facing traffic.

The IANA Service Name and Transport Protocol Port Number Registry lists port 403 as dual-registered for both TCP and UDP under the name "decap," with no description text, no assignee, and a blank Reference column — there is no RFC or standards document tied to this port.

The name "decap" is commonly guessed within the security community to stand for "decapsulation," but this is unverified speculation rather than a documented protocol meaning; no authoritative source describes an actual service running under that name, and no vendor, blog, or forum documentation names real software that generates traffic here.

No malware or trojan family has been associated with 403/udp in the port-database trojan checks available. SANS Internet Storm Center's live port-403 tracker shows only routine, low-level internet background-radiation scanning at an overall "green" (low) threat level, consistent with an obscure, rarely-used port rather than an actively exploited one.

One dated community sighting exists: on 2000-10-09, James Hoagland of Silicon Defense reported a scan of TCP port 403 on the SecurityFocus/Bugtraq "incidents" mailing list and asked whether anyone knew the actual purpose of "decap"; the thread received no definitive answer.

IANA assignment
decap — no description text; Reference column blank; no assignee listed; dual-registered 403/tcp + 403/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Prevalence
0.001021 (nmap-services open-frequency) [Confirmed] — this site's own tooling
Related ports
403/tcp (same dual-registered "decap" entry, no elaborated use)

Primary use

no documented protocol or specification exists; the name is commonly guessed as "decapsulation" but this is unverified

[Likely] — seclists.org Bugtraq thread, t1shopper port lookup

Other/unofficial uses

Unknown — no vendor, blog, or forum documentation names software using 403/udp; port-lookup aggregator sites merely restate the bare "decap" label

[Unknown] — SpeedGuide, GRC Port Authority, auditmypc

Security implications

no known malware/trojan association found; SANS ISC shows routine low-level background scanning at "green" (low) threat; treat an open 403/udp as anomalous

[Likely] — SANS ISC port/403, auditmypc, GRC

Typically seen on

essentially never in legitimate production use; appears mainly in scan datasets and port-lookup aggregator lists [Likely]

Analyst note
A responsive 403/udp is statistically unusual and lacks a confirmed protocol identity — investigate as a possible decoy, misconfiguration, or non-standard service rather than assuming a known application.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
decap UDP 0.10%
decap TCP 0.00%
IANA name
decap
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.