480
Summary
- // typical exposure
- Anomalous (rarely legitimately open) — No documented protocol, vendor, or legitimate deployment pattern exists for 480/tcp under either its IANA name ("iafdbase") or its nmap-services name ("loadsrv"), and open-frequency telemetry shows it almost never open, so any listener here is a fingerprinting or anomaly signal rather than expected service traffic.
- // analyst note
- Two different service names appear for this port depending on the data source (IANA's
iafdbasevs. nmap-services'loadsrvon the TCP side) and neither maps to a documented protocol or named application — do not assume either label identifies the actual software behind an open port 480. - // if you see it open
- No CVE referencing 480/tcp is recorded in the NVD as of an August 2026 search. No malware/trojan association was found. SANS ISC's port-480 page shows only routine internet background-scan noise, not a documented targeted campaign. The port is almost never observed open and has no documented legitimate protocol, so real traffic on it should be treated as anomalous and investigated.
About port 480/tcp.
Port 480/tcp carries no documented protocol; it is a sparsely-used registered port with no evidence of legitimate public-facing use, so it should generally stay internal-only or simply closed rather than exposed to the internet. IANA registers 480 on both TCP and UDP as iafdbase, assignee Rick_Yazwinski, with a blank Reference column and no description beyond the name itself.
The companion port 479 is registered under the name iafserver, suggesting the pair was meant to work together, but the 479 rows carry no assignee at all — IANA's Assignee and Contact columns for iafserver are empty, unlike 480's iafdbase rows which name Rick_Yazwinski. So the iafserver/iafdbase pairing rests on the adjacent registered names and shared numbering alone, not on a shared registrant. IANA publishes no RFC or specification for either, and no protocol document describes what "iafdbase" actually does on the wire.
Separately, the nmap-services corpus (used by Nmap and mirrored in this site's port-data artifact) labels 480/tcp specifically as loadsrv — a different name than the IANA iafdbase registration — while keeping iafdbase as the label for 480/udp. Neither name is tied to a known, named application in any source found; a claimed link to Software AG's unrelated "Integrated Authentication Framework" product is unverified speculation and is not asserted here.
Real-world visibility is minimal: nmap-services open-frequency for 480/tcp is about 0.0013%, and SANS ISC's port-480 tracker shows only routine internet background-scan noise rather than a documented targeted campaign. No CVE referencing port 480/tcp is recorded in the NVD as of an August 2026 search, and no malware/trojan association was found for it as of the same search.
- IANA assignment
iafdbase— description "iafdbase"; reference (blank); assignee Rick_Yazwinski; dual-registered 480/tcp + 480/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/tcp; the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/udp- Range class
- system/well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/tcp
- Prevalence
- nmap-services open-frequency 480/tcp = 0.000013 (~0.0013%); 480/udp = 0.000461 (~0.046%) [Confirmed] — this site's own tooling
- Related ports
- 479/tcp,udp (
iafserver, no assignee recorded — the pairing with 480'siafdbaserests on adjacent naming, not a shared registrant) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iafserver 479/tcp
Primary use
Unknown — IANA lists the name pair only, with no RFC or protocol description; the companion 479/tcp,udp is registered iafserver with no assignee recorded [Confirmed registration / Unknown protocol] — the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/tcp
Other/unofficial uses
nmap-services labels 480/tcp specifically as loadsrv (distinct from the IANA iafdbase name, which nmap-services applies to 480/udp instead); no vendor/software identity confirmed for either label
Security implications
no CVE, no confirmed malware association, and only routine background scan noise observed; the port is essentially unused and undocumented, so an unexpected listener merits investigation
Typically seen on
not typically seen open on any known platform; treat any hit as anomalous [Unknown]
- Analyst note
- Two different service names appear for this port depending on the data source (IANA's
iafdbasevs. nmap-services'loadsrvon the TCP side) and neither maps to a documented protocol or named application — do not assume either label identifies the actual software behind an open port 480.
About port 480/udp.
Port 480/udp carries the IANA-registered service name iafdbase, but no confirmed real-world application or published protocol spec exists for it, so it should not be treated as a legitimate service to expose to the public internet — an open 480/udp is best read as anomalous and worth investigating rather than trusted as routine.
IANA lists 480/udp as iafdbase, assignee Rick Yazwinski, with a blank Reference field and no Registration or Modification date on file. IANA registers iafdbase on both 480/tcp and 480/udp — there is no separate loadsrv entry anywhere in the IANA registry. The name loadsrv (description "iafdbase") is a label carried in the nmap-services database, mirrored in this repo's this site's own tooling, for 480/tcp; it is a database naming discrepancy between nmap-services and IANA, not a second, overlapping, or legacy duplicate IANA registration.
No vendor documentation, RFC, or product page describing an actual wire protocol for iafdbase was found. One Experts Exchange forum thread ("What is iafserver and iafdbase (ports 479 & 480)") shows at least one administrator investigated this exact port pairing after seeing unexplained traffic, but the thread's content could not be retrieved (403 Forbidden), so no software can be credibly attributed from it.
The port is not listed on Gary Kessler's maintained Bad TCP/UDP Ports (trojan) list as of an August 2026 search. SANS Internet Storm Center shows only low, green-level background scanning on the port, consistent with routine internet-wide sweeps rather than a targeted campaign.
- IANA assignment
iafdbase— description "iafdbase"; Reference field blank; assignee Rick_Yazwinski; IANA registersiafdbaseon both 480/tcp and 480/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/tcp; the IANA Service Name and Transport Protocol Port Number Registry iafdbase 480/udp- Range class
- well-known (0–1023), IANA "system" range [Confirmed] — this site's own tooling
- Prevalence
- this site's own tooling open-frequency 480/udp (iafdbase) = 0.000461; sibling 480/tcp (nmap-services label
loadsrv) = 0.000013 [Confirmed] — this site's own tooling - Related ports
- 479/tcp+udp (
iafserver, believed paired by naming convention with iafdbase; pairing not independently verified beyond the registry name and one unresolved forum thread) [Unknown]
Primary use
no confirmed protocol or application; the bare IANA name is the only documented fact
Other/unofficial uses
none confirmed; one unresolved forum thread references the 479/480 pairing but its content could not be fetched (403)
Security implications
not on Gary Kessler's Bad Ports (trojan) list as of August 2026; SANS ISC shows low, green-level, non-targeted scanning; no CVE found tied to this port or service as of an August 2026 search
Typically seen on
no confirmed hosts or products; observed activity is more consistent with scanning noise than a deployed service [Unknown]
- Analyst note
- An open 480/udp with no confirmed application behind it should be treated as anomalous — investigate the source rather than assume a legitimate service.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| iafdbase | UDP | — | 0.05% |
| loadsrv | TCP | iafdbase | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.