454
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — The IANA 'contentserver' registration carries no protocol spec, real-world usage is limited to a single unverified report of internal Azure infrastructure traffic, and measured open-prevalence is near zero, so a live listener merits investigation rather than treatment as a routine public service.
- // common applications
- Microsoft Azure Websites (App Service), Traffic on this port is most often internet background-scan noise; a single hedged 2015 Microsoft forum report has attributed some occurrences to internal Azure Websites (App Service) infrastructure communication, unconfirmed by formal Microsoft documentation.
- // analyst note
- A registered-but-unspecified port with near-zero observed prevalence — a live 454/tcp listener is unusual enough to warrant investigation rather than routine dismissal.
- // if you see it open
- No CVE or named malware family is recorded against 454/tcp as of an August 2026 search. SANS ISC's live port-454 page showed only routine, low-volume internet background-scan traffic with a green threat level as of the same check. The port has no documented protocol spec, so an unexpected live listener should be investigated rather than assumed benign.
About port 454/tcp.
Port 454/tcp is registered with IANA under the service name contentserver ("ContentServer"), but the registry carries no RFC or protocol reference and no widely-documented application defines a single canonical use for it — it should stay internal-only rather than be exposed to the public internet.
IANA lists contentserver for both 454/tcp and 454/udp, with the assignee and reference columns blank; no protocol specification accompanies the entry. That leaves the port formally registered but functionally undefined, which is itself a mild yellow flag for an analyst evaluating a live listener.
The one concrete, attributable real-world sighting is a 2015 Microsoft support-forum thread (archived, now on learn.microsoft.com) in which a Microsoft-affiliated responder tells a user that ports 454 and 455 flagged by a security scan on an Azure Website are internal Azure Websites (App Service) infrastructure communication and safe to ignore. This is single-source, dated, and unconfirmed by any formal Microsoft documentation.
As of an August 2026 check, SANS ISC's port-454 activity page shows only routine, low-volume internet background-scan traffic and lists the port's threat level as green — no elevated concern, no known targeted campaign. No CVE or named malware family tied specifically to 454/tcp was found as of this search.
- IANA assignment
contentserver— "ContentServer"; reference (blank — no RFC cited); assignee blank; dual-registered 454/tcp + 454/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry contentserver 454/tcp- Range class
- system/well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry contentserver 454/tcp
- Prevalence
- nmap-services open-frequency 454/tcp ≈ 0.000038 (~0.0038%); 454/udp ≈ 0.000329 (~0.033%) [Confirmed] — this site's own tooling (454)
- Related ports
- 455/tcp (named alongside 454 in the same Azure forum report); the
/port/hub
Primary use
no documented protocol or specification; IANA registration is a name/description pair only
Other/unofficial uses
reported (single-source, 2015, hedged) as internal Microsoft Azure Websites/App Service infrastructure communication
Security implications
no CVE or malware family documented as of August 2026; SANS ISC shows only routine background scanning, threat level green [Confirmed for scan data / Unknown for malware] — https://isc.sans.edu/data/port/454
Typically seen on
possibly Microsoft Azure Websites (App Service) infrastructure hosts (single hedged report); otherwise unclear / anomaly if seen elsewhere [Likely/Unknown]
- Analyst note
- A registered-but-unspecified port with near-zero observed prevalence — a live 454/tcp listener is unusual enough to warrant investigation rather than routine dismissal.
About port 454/udp.
Port 454/udp is registered with IANA under the service name contentserver (description "ContentServer"), but no RFC or vendor specification is published for it, so whether it belongs on the public internet cannot be confirmed from available research — treat it as internal-only pending better documentation rather than assume it is safe to expose.
The IANA registry lists contentserver on both 454/tcp and 454/udp, with blank Assignee and Reference columns — there is no owning organization or protocol document tied to the entry, which is unusual for a long-standing well-known-range assignment.
Several secondary port-lookup sites (SpeedGuide, adminsub.net) describe TCP port 454 as "Apple Filing Protocol (AFP) over TLS/SSL." This conflicts with the current blank-reference IANA entry and none of those pages cite a primary source, so the AFP claim is flagged as an unverified, likely-outdated secondary-source claim rather than treated as fact.
SANS Internet Storm Center shows only sporadic, low-volume scanning against the port and rates its current threat level "green" as of an August 2026 check, with no CVE on record. The one concrete, citable usage report is a 2015 Microsoft support-forum thread in which a Microsoft responder confirmed ports 454 and 455 are used for internal Azure Websites infrastructure communication and "cannot be turned off" — a dated, platform-specific sighting, not a general statement about the port today.
- IANA assignment
contentserver— "ContentServer"; Reference column blank; Assignee blank; dual-registered 454/tcp + 454/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry contentserver 454/udp- Range class
- well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry contentserver 454/udp
- Prevalence
- nmap-services open-frequency 454/udp ≈ 0.000329 (~0.033%); 454/tcp ≈ 0.000038 [Confirmed] — this site's own tooling
- Related ports
- 454/tcp (dual IANA registration, same blank-reference entry); port 455 (named alongside 454 in the same Azure forum report) [Confirmed/Likely]
Primary use
Unknown — IANA carries only the bare service name and description "ContentServer" with no RFC or specification behind it
Other/unofficial uses
single dated (2015) report of ports 454/455 used for internal Microsoft Azure Websites infrastructure communication (TLSv1, RC4-SHA/DES-CBC3-SHA offered), stated by a Microsoft forum responder to be non-site-specific and non-disable-able
Security implications
no CVE on record and no verified malware association as of an August 2026 search; SANS ISC shows sporadic low-volume scanning with threat level "green" as of the same check; a common third-party "AFP over TLS" description for TCP 454 conflicts with the blank-reference IANA entry and is unsourced
Typically seen on
hosts carrying an undocumented "ContentServer" listener (rare); isolated Microsoft Azure Websites infrastructure, per one dated forum report [Unknown/Likely]
- Analyst note
- An open 454/udp has no published protocol behind it — verify context locally before trusting third-party "AFP" labels, and treat as low-prevalence and poorly documented rather than a known, expected service.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| contentserver | UDP | — | 0.03% |
| contentserver | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.