Network port detail · UDP/TCP

410

Decladebug
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// typical exposure
Anomalous (rarely legitimately open) — Decladebug is a legacy DEC/HP remote-debugging protocol with no documented modern deployment or application usage, so a responsive port 410 is essentially never legitimate and warrants investigation rather than being treated as expected internal service traffic.
// analyst note
A responsive port 410 has no documented legitimate modern use — treat it as a legacy artifact or anomaly and investigate rather than assume normal service traffic.
// if you see it open
No virus/trojan association is reported by third-party port databases (AuditMyPC); no CVE was identified against this port. The protocol has no documented modern deployment, so a responsive port 410 is essentially always a legacy remnant or anomaly rather than expected traffic, and should never be reachable from the public internet.
[ 01 ] — Context

About port 410/tcp.

Updated  ·  Confidence: Medium

Port 410/tcp carries decladebug, the DECLadebug Remote Debug Protocol — a legacy Digital Equipment Corporation (DEC) remote-debugging service now attributed to Hewlett Packard in the IANA registry — and no source found in this pass documents any modern application generating traffic on it, so it should never be exposed to the public internet.

IANA registers 410 on both TCP and UDP under the service name decladebug, description "DECLadebug Remote Debug Protocol," with assignee/contact listed as Hewlett Packard and a blank Reference column (no RFC is associated with this assignment).

The protocol's likely origin is DEC's "Ladebug" debugger from the OpenVMS/Tru64 UNIX era, which used a network protocol to attach to and control processes on a remote host; Hewlett Packard's listing as assignee reflects HP's later acquisition of DEC's Compaq successor rather than a fresh HP-originated protocol.

No third-party source — vendor documentation, blog, forum, or port-lookup aggregator — was found describing any current software that generates traffic on port 410. Aggregators such as SpeedGuide and AuditMyPC simply restate the IANA assignment; AuditMyPC additionally reports no known virus/trojan association for the port.

IANA assignment
decladebug — "DECLadebug Remote Debug Protocol"; reference (blank — no RFC cited); assignee/contact Hewlett Packard; dual-registered 410/tcp + 410/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Prevalence
nmap-services open-frequency 410/tcp ~0.000025 [Confirmed] — this site's own tooling
Related ports
other legacy DEC-registered System Ports; contrast modern remote-debugging conducted over SSH tunnels rather than a dedicated well-known port

Primary use

remote debug protocol, likely tied to DEC's "Ladebug" debugger for OpenVMS/Tru64 UNIX-era remote process debugging; not a widely deployed modern protocol

[Likely] — IANA registry context, no RFC available

Other/unofficial uses

none documented in this research pass [Unknown]

Security implications

no virus/trojan association reported by AuditMyPC; no CVE identified against this port; essentially no documented legitimate modern usage

[Likely] — AuditMyPC

Typically seen on

legacy DEC/HP OpenVMS or Tru64 UNIX systems that historically ran the Ladebug remote-debug service; otherwise anomalous [Likely]

Analyst note
A responsive port 410 has no documented legitimate modern use — treat it as a legacy artifact or anomaly and investigate rather than assume normal service traffic.
[ 02 ] — Context

About port 410/udp.

Updated  ·  Confidence: Medium

Port 410/udp is registered with IANA as decladebug, the DECLadebug Remote Debug Protocol; it has no legitimate role on the public internet and should stay internal-only, if it is running anywhere at all.

The IANA registry lists the service name decladebug, description "DECLadebug Remote Debug Protocol," and assignee Hewlett Packard (the registration traces back through DEC/Compaq to HP, following that product lineage). The port is dual-registered on both TCP and UDP. No RFC is cited in the IANA Reference field, so it stays blank rather than guessed.

DECLadebug is a legacy vendor remote-debugging protocol originating with Digital Equipment Corporation, tied to the Ladebug debugger used on DEC/Compaq/HP systems (the Tru64 UNIX era). It let a remote client attach to and debug a running process over the network — useful for vendor engineering workflows, not a general-purpose service.

No current, widely-used consumer or open-source software is documented as using this port; this research pass found no credible community sightings beyond the historical DEC/Ladebug tie, so no other application attribution is made.

IANA assignment
decladebug — "DECLadebug Remote Debug Protocol"; reference (blank — no RFC cited in IANA registry); assignee Hewlett Packard; dual-registered 410/tcp + 410/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0-1023) [Confirmed]
Prevalence
nmap-services open-frequency 410/udp ~0.000494 [Confirmed] — this site's own tooling
Related ports
other legacy DEC/vendor-assigned ports in the 400s range; contrast modern remote-debug tooling (e.g. gdbserver, LLDB remote protocol) which use ephemeral/configurable ports rather than a fixed IANA assignment

Primary use

DECLadebug Remote Debug Protocol — remote process debugging for DEC/Compaq/HP systems (Ladebug debugger lineage, Tru64 UNIX era)

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Other/unofficial uses

none documented; no credible community sightings of other software using this port surfaced in this research pass [Unknown]

Security implications

essentially never legitimately open today; AuditMyPC's historical port database carries a generic malware-caveat template but explicitly marks this port "Virus/Trojan: No"; no CVE or active-exploitation reporting found

[Likely] — https://www.auditmypc.com/udp-port-410.asp

Typically seen on

legacy DEC/Compaq/HP vendor debug tooling if anywhere; otherwise an anomaly worth investigating [Likely]

Analyst note
A responsive 410/udp listener is statistically rare; treat as a legacy-system fingerprint or anomaly rather than expected infrastructure.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
decladebug UDP DECLadebug Remote Debug Protocol 0.05%
decladebug TCP DECLadebug Remote Debug Protocol 0.00%
IANA name
decladebug
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.