403
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No legitimate protocol or software is documented as using 403/tcp; the bare 'decap' IANA entry has no deployed service, so a responsive port 403 is atypical and warrants investigation rather than being treated as routine service traffic.
- // analyst note
- Port 403/tcp has no documented legitimate service; treat any activity here as anomalous and worth investigating rather than routine.
- // if you see it open
- No CVE or malware family is confirmed to be associated with 403/tcp. A 2000-era SecLists incidents thread discusses unexplained/anomalous traffic on the port under the 'decap?' name. SANS Internet Storm Center tracks per-port attack activity for 403 among its scanned-port dashboards, but volumes/trends could not be verified. Because no legitimate application is documented, an open or probed port 403 should be treated as atypical.
About port 403/tcp.
Port 403/tcp carries no documented, actively used protocol; IANA lists it only under the bare service name "decap" with no assignee and no reference, so it should be treated as an unused or anomalous port rather than one appropriate to expose to the public internet.
IANA's Service Name and Transport Protocol Port Number Registry assigns 403 to "decap" on both TCP and UDP, a legacy entry with blank Assignee and Reference fields. The name is widely believed, though not confirmed by any RFC, to abbreviate "decapsulation." The entry appears to date from the RFC 1700-era registry consolidation of 1994 rather than from a maintained specification.
No modern client or server software could be confirmed as using this port. Searches surfaced only generic port-lookup directory mirrors (speedguide.net and similar sites) that restate the bare IANA line without documenting any real deployment, vendor product, or protocol behavior tied to port 403.
A 2000-era SecLists incidents thread discusses unexplained, anomalous traffic observed on TCP port 403 under the "decap?" name, and SANS Internet Storm Center maintains a per-port attack-activity tracking page for 403, indicating it appears among the long tail of ports monitored for scanning activity — though specific volumes or trends could not be verified.
- IANA assignment
decap— no description beyond the bare service name; assignee blank; reference blank (no RFC cited); dual-registered 403/tcp + 403/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (line 799); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency for 403/tcp ≈ 0.000025 [Confirmed] — this site's own tooling
- Related ports
- none specifically documented as related [Unknown]
Primary use
none confirmed/deployed; legacy IANA name "decap" (believed to mean "decapsulation," unconfirmed), an RFC 1700-era (1994) entry with no dedicated specification
Other/unofficial uses
none credibly documented; only generic port-directory mirror sites restate the bare IANA entry
Security implications
no confirmed CVE or malware family; a 2000-era SecLists thread reports unexplained/anomalous traffic under the "decap?" name; SANS ISC tracks the port on its per-port attack-activity dashboard (content/volumes unverified)
Typically seen on
no confirmed legitimate deployment; a responsive port 403 is atypical and should be investigated as anomalous or probed traffic [Unknown]
- Analyst note
- Port 403/tcp has no documented legitimate service; treat any activity here as anomalous and worth investigating rather than routine.
About port 403/udp.
Port 403/udp is registered with IANA under the name decap, but no protocol specification, vendor documentation, or widely-used software has been confirmed to run on it, so a responsive 403/udp should be treated as anomalous rather than expected internet-facing traffic.
The IANA Service Name and Transport Protocol Port Number Registry lists port 403 as dual-registered for both TCP and UDP under the name "decap," with no description text, no assignee, and a blank Reference column — there is no RFC or standards document tied to this port.
The name "decap" is commonly guessed within the security community to stand for "decapsulation," but this is unverified speculation rather than a documented protocol meaning; no authoritative source describes an actual service running under that name, and no vendor, blog, or forum documentation names real software that generates traffic here.
No malware or trojan family has been associated with 403/udp in the port-database trojan checks available. SANS Internet Storm Center's live port-403 tracker shows only routine, low-level internet background-radiation scanning at an overall "green" (low) threat level, consistent with an obscure, rarely-used port rather than an actively exploited one.
One dated community sighting exists: on 2000-10-09, James Hoagland of Silicon Defense reported a scan of TCP port 403 on the SecurityFocus/Bugtraq "incidents" mailing list and asked whether anyone knew the actual purpose of "decap"; the thread received no definitive answer.
- IANA assignment
decap— no description text; Reference column blank; no assignee listed; dual-registered 403/tcp + 403/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- 0.001021 (nmap-services open-frequency) [Confirmed] — this site's own tooling
- Related ports
- 403/tcp (same dual-registered "decap" entry, no elaborated use)
Primary use
no documented protocol or specification exists; the name is commonly guessed as "decapsulation" but this is unverified
Other/unofficial uses
Unknown — no vendor, blog, or forum documentation names software using 403/udp; port-lookup aggregator sites merely restate the bare "decap" label
Security implications
no known malware/trojan association found; SANS ISC shows routine low-level background scanning at "green" (low) threat; treat an open 403/udp as anomalous
Typically seen on
essentially never in legitimate production use; appears mainly in scan datasets and port-lookup aggregator lists [Likely]
- Analyst note
- A responsive 403/udp is statistically unusual and lacks a confirmed protocol identity — investigate as a possible decoy, misconfiguration, or non-standard service rather than assuming a known application.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| decap | UDP | — | 0.10% |
| decap | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.