479
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No application has ever been confirmed to use 479/tcp, so it has no legitimate reason to be reachable and any observed traffic should be treated as an investigation trigger.
- // analyst note
- with no confirmed application behind it, a responsive 479/tcp is best treated as an anomaly to investigate rather than a recognized service.
- // if you see it open
- No confirmed application has ever been attributed to 479/tcp, so the port has no established legitimate reason to be exposed. A search-engine auto-summary claiming Back Orifice trojan use could not be traced to a source and conflicts with Back Orifice's documented ports (UDP 31337 classic; UDP 54320/54321 for BO2K), so it is not asserted. An Experts Exchange thread shows at least one administrator asked about the port, but its content was inaccessible (HTTP 403) as of an August 2026 search.
About port 479/tcp.
Port 479/tcp is registered with IANA as iafserver, but no vendor, RFC, or community source confirms what actually runs on it, so it should be treated as anomalous — no evidence supports exposing it to the public internet, and unexpected traffic here is a signal worth investigating rather than routine service activity.
The IANA registry lists iafserver on both 479/tcp and 479/udp with blank Assignee and Reference columns: no RFC, no contact, and no description text beyond the service name itself. The adjacent port 480 is separately registered as iafdbase, also unreferenced, which suggests the pair may once have named a coordinated client/server product — but nothing in the registry confirms that link.
An August 2026 search for real-world usage turned up little. An Experts Exchange forum thread titled after iafserver and iafdbase (ports 479 and 480) shows at least one administrator once asked what the ports were, but the thread body returned an HTTP 403 error and could not be read, leaving its actual answer Unknown. IBM ClearCase, which surfaces near port 479 in some search indexes, was checked directly and documents port 371 instead, ruling it out as a source for this port.
No dedicated exposure telemetry (Shodan/Censys counts, SANS ISC top-ports data) specific to 479/tcp was found, and the repo's nmap-services snapshot records the port as almost never observed open. A search-engine auto-summary claiming the port is used by the Back Orifice trojan could not be traced to any real source page and contradicts Back Orifice's documented ports, so that claim is treated as unverified rather than fact.
- IANA assignment
iafserver— Reference column blank, Assignee column blank; dual-registered 479/tcp + 479/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iafserver 479/tcp- Range class
- well-known (0–1023) [Confirmed] — this site's own tooling (range: "system")
- Prevalence
- nmap-services open-frequency 479/tcp = 0.000013 (~0.0013%), 479/udp = 0.000675 (~0.0675%) [Confirmed] — this site's own tooling
- Related ports
- 480/tcp+udp (
iafdbase, the paired adjacent registry entry) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/tcp
Primary use
undocumented; the IANA registry provides only the service name with no protocol specification, RFC, or contact
Other/unofficial uses
none confirmed
Malware association
none confirmed; an unsourced Back Orifice claim was checked and rejected as it conflicts with Back Orifice's documented ports
Typically seen on
no known typical host or application; registry-only assignment [Unknown]
- Analyst note
- with no confirmed application behind it, a responsive 479/tcp is best treated as an anomaly to investigate rather than a recognized service.
About port 479/udp.
Port 479/udp carries no independently documented protocol; it is registered with IANA only under the bare label iafserver with no expanded description, no RFC reference, and no known software attribution, so it should be treated as internal/anomalous rather than something expected to face the public internet.
The IANA Service Name and Transport Protocol Port Number Registry lists 479 as dual-registered on both TCP and UDP under the identical name iafserver, with the description field simply repeating the service name and no assignee, reference, or registration date recorded. No RFC or vendor specification defining an "iafserver" protocol was located.
A lead investigating Aladdin/SafeNet HASP license-manager software (whose name superficially resembles the "IAF" abbreviation) was checked and ruled out: HASP's documented ports are 475/tcp (tcpnethaspsrv) and 1947/tcp (hasplm), not 479. One Experts Exchange forum thread title ("What is iafserver and iafdbase (ports 479 & 480)") shows users have historically asked the same question, but the thread body returned a 403 error and could not be read, so it is cited only as evidence the question has been asked, not as a confirmed software attribution.
A general web search surfaced a claim linking TCP/479 to the BackOrifice trojan, but this claim could not be traced to any identifiable source page, and it conflicts with Back Orifice's documented ports (UDP 31337 classic; UDP 54320/54321 for BO2K). On that basis alone — an untraceable claim contradicted by Back Orifice's own documented ports — it is treated as unverified and likely spurious.
- IANA assignment
iafserver— description field repeats the service name with no expansion; reference blank; assignee blank; dual-registered 479/tcp + 479/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iafserver 479/udp- Range class
- system/registered (0–1023 boundary; 479 falls in the well-known/system range) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iafserver 479/udp
- Prevalence
- nmap-services open-frequency 479/udp = 0.000675 (~0.0675%); 479/tcp = 0.000013 (~0.0013%) [Confirmed] — this site's own tooling (port 479)
- Related ports
- 480/tcp+udp (
iafdbase, same registry naming pattern and same Experts Exchange thread); 475/tcp (tcpnethaspsrv, ruled-out HASP lead) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry
Primary use
Unknown — no RFC or vendor specification for "iafserver" was found
Other/unofficial uses
none confirmed; HASP/Aladdin license-manager software ruled out (uses 475/tcp and 1947/tcp instead)
Security implications
no confirmed malware/trojan association; a repeated "BackOrifice on TCP/479" claim traces to no identifiable source page and conflicts with Back Orifice's documented ports, so it is not treated as evidence [Unknown/Threat-reported (unverified)]
Typically seen on
Unknown — no confirmed host/software population identified [Unknown]
- Analyst note
- Traffic on 479/udp lacks a documented legitimate driver; treat an open instance as worth investigating rather than assuming a known application.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| iafserver | UDP | — | 0.07% |
| iafserver | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.