407
Summary
- // typical exposure
- Restricted (trusted networks only) — Timbuktu is a legitimate but full remote-desktop-control product, so exposing 407/tcp to the public internet carries the same unauthorized-access risk as any exposed remote-access service and it should be limited to trusted networks or a VPN.
- // common applications
- TimbuktuTimbuktu Pro Traffic on this port is most often the Timbuktu / Timbuktu Pro remote-control application's control channel; community sources report no other mainstream software commonly using TCP 407, though it is a legacy, largely discontinued product so current sightings are expected to be rare relative to its measured 0.001129 nmap-services open frequency.
- // analyst note
- An open 407/tcp today most likely reflects a legacy Timbuktu Pro deployment or stale configuration; treat as a remote-access exposure risk to investigate rather than a normal internet-facing service. The measured nmap-services frequency (0.001129) supports "legacy but genuinely deployed" rather than "purely historical."
- // if you see it open
- Full remote-control/screen-sharing product; legitimate exposure model is trusted-network/VPN only, not the public internet. GIAC/SANS documents potential vulnerabilities in Timbuktu remote-control software; Timbuktu Pro 2.0/5.2.1 has a published DoS exploit (Exploit-DB #19750). auditmypc.com's port-407 page explicitly records a 'Virus / Trojan: No' verdict; its trojan-adjacent language is site-wide template boilerplate, not a port-specific finding, so no credible source confirms a trojan/backdoor association for 407/tcp.
About port 407/tcp.
Port 407/tcp carries the control channel for Timbuktu (later Timbuktu Pro), a remote-control, screen-sharing, file-transfer, and chat application; it should stay restricted to trusted networks or a VPN rather than being exposed to the public internet, since it functions as a full remote-desktop-control service.
IANA registers 407 for both TCP and UDP under the service name timbuktu, assignee Marc Epard, with a blank Reference field — this is a legitimate, long-standing registration rather than an unassigned or dynamic port, but it is tied to a service name, not an RFC.
Timbuktu was originally built by Farallon, which renamed to Netopia in 1999; Netopia was acquired by Motorola in 2007, and Motorola's Home business (including Timbuktu) was later sold to ARRIS in 2013. Community and vendor sources describe a protocol-version split: Timbuktu 5.1 and earlier initiated connections over UDP/407, while 5.2 and later used TCP/407, and remote access required a static IP plus router/firewall forwarding of port 407.
Timbuktu is a legacy, effectively discontinued product whose active commercial life ran roughly through the 2000s into the early 2010s. No exact end-of-life date could be verified, so it is left unstated rather than fabricated. The nmap-services open-frequency figure for 407/tcp is a measured 0.001129 — a genuinely non-trivial figure for a legacy service, consistent with real (if declining) deployment rather than pure historical noise.
- IANA assignment
timbuktu— "Timbuktu"; reference (blank — no RFC cited); assignee Marc Epard; dual-registered 407/tcp + 407/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency for 407/tcp = 0.001129 [Confirmed] — this site's own tooling (canonical in-repo measured-frequency artifact)
- Related ports
- 407/udp (same service, protocol versions 5.1 and earlier); contrast other remote-control protocols such as 3389/tcp (RDP) and 5900/tcp (VNC)
Primary use
control-channel port for Timbuktu / Timbuktu Pro, a remote-control, screen-sharing, file-transfer, and chat application (Farallon → Netopia → Motorola → ARRIS) [Confirmed] — https://en.wikipedia.org/wiki/Timbuktu_(software), https://www.networkworld.com/article/837939/software-timbuktu-pro-from-netopia.html
Other/unofficial uses
none independently corroborated beyond Timbuktu; aggregator/scanner listings (SpeedGuide, t1shopper, auditmypc) all trace back to the same assignment
Security implications
legitimate full remote-control product requiring VPN/trusted-network-only exposure; documented GIAC/SANS vulnerability catalog and an Exploit-DB DoS (#19750) for Timbuktu Pro 2.0/5.2.1; auditmypc.com's port-407 page explicitly records "Virus / Trojan: No," with no confirmed trojan/backdoor association [Confirmed] — https://www.giac.org/paper/gsec/2227/potential-vulnerabilities-timbuktu-remote-control-software/103796, https://www.exploit-db.com/exploits/19750, https://www.auditmypc.com/tcp-port-407.asp
Typically seen on
legacy Mac/Windows hosts running Timbuktu Pro (roughly 2000s–early 2010s); otherwise an anomalous/leftover exposure
- Analyst note
- An open 407/tcp today most likely reflects a legacy Timbuktu Pro deployment or stale configuration; treat as a remote-access exposure risk to investigate rather than a normal internet-facing service. The measured nmap-services frequency (0.001129) supports "legacy but genuinely deployed" rather than "purely historical."
About port 407/udp.
Port 407/udp carries Timbuktu, a discontinued remote-control and remote-desktop product; it should stay restricted to trusted networks rather than exposed to the public internet. Scan-survey data also shows the port measurably more open in the wild than its legacy status alone would suggest, so a reachable 407/udp today is better read as an under-secured legacy holdover worth locking down than as something categorically unexpected.
Timbuktu began as a Macintosh remote-control tool from Farallon Computing, which renamed itself Netopia in 1999. Netopia was acquired by Motorola in February 2007, and Motorola's successor Arris announced the end of Timbuktu development on April 28, 2015, with a roughly 90-day sales wind-down. The product is no longer maintained.
Per community technical writeups, Timbuktu versions 5.1 and earlier used UDP port 407 for session negotiation and initial credential exchange before handing off to a TCP session on the same port number; versions 5.2 and later shifted primarily to TCP/407. This makes the UDP side of the port an artifact of older client versions rather than the product's current (pre-discontinuation) default path.
IANA's registry lists 407 as timbuktu, dual-registered on both TCP and UDP, with assignee [Marc_Epard] and a blank Reference column — no RFC was ever published for it, so none is cited here.
- IANA assignment
timbuktu— "Timbuktu"; reference (blank — no RFC cited); assignee[Marc_Epard]; dual-registered 407/tcp + 407/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (lines 807–808); IANA service-names-port-numbers registry- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- nmap-services open-frequency 0.005305 for 407/udp — the highest figure in this batch of ports and about 4.7x the 0.001129 figure for 407/tcp [Confirmed] — this site's own tooling
- Related ports
- 407/tcp (dual registration, same service); other remote-control/remote-desktop ports (3389/tcp RDP, 5900/tcp VNC) for contrast
Primary use
Timbuktu remote-control/remote-desktop and file-transfer software (Farallon → Netopia → Motorola → Arris); UDP/407 used for session negotiation/credential exchange in versions ≤5.1 before falling back to TCP/407, with 5.2+ shifting primarily to TCP
Other/unofficial uses
none confirmed in this pass; a light community-sightings search (SpeedGuide, PortsMaster, forums, vendor docs) turned up no non-Timbuktu software reported using 407/udp
Security implications
documented DoS/vulnerability history in Netopia Timbuktu Pro Remote Control software; AuditMyPC's checked verdict for this port is "Virus / Trojan: No" — no confirmed malware association [Confirmed for the negative verdict; Likely for the DoS history] — https://www.giac.org/paper/gsec/2227/potential-vulnerabilities-timbuktu-remote-control-software/103796, https://www.exploit-db.com/exploits/19750, https://www.auditmypc.com/udp-port-407.asp
Typically seen on
legacy Mac/Windows hosts still running discontinued Timbuktu Pro remote-control software
- Analyst note
- Timbuktu was discontinued in 2015; 407/udp nonetheless shows the highest measured open-frequency in this batch, so an open instance is best treated as a legacy remote-access exposure that should be restricted rather than left reachable.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| timbuktu | UDP | — | 0.53% |
| timbuktu | TCP | — | 0.11% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.