504
Summary
- // typical exposure
- Internet-facing — Citadel's port 504 protocol exists specifically so remote clients can reach a groupware/BBS server over the network, similar in design intent to other mail-access ports, rather than being an internal-only management channel.
- // common applications
- Citadel/UXCitadel Server Traffic on this port is most often native Citadel groupware/BBS client-server protocol activity to a Citadel/UX (or compatible fork) server; no other software has been reported using this port.
- // analyst note
- an open 504/tcp is the Citadel groupware protocol's expected remote-client endpoint — legitimate on a known Citadel/UX deployment, but worth confirming given how rarely the assignment appears open in scan data.
- // if you see it open
- No CVE is recorded in the NVD specifically for 504/tcp, and no malware or trojan association was found, as of an August 2026 search. As the port that accepts remote Citadel client connections, it should require authenticated, encrypted access and be firewalled/VPN-restricted for deployments not meant to serve the general public.
About port 504/tcp.
Port 504/tcp carries the native client-server protocol for Citadel groupware and BBS-style servers; it is designed to accept remote client connections from across the public internet — similar in intent to other mail-access ports — rather than being restricted to an internal management network, though operators should still require authenticated, encrypted client access.
IANA registers 504 as citadel on both TCP and UDP, assigned to [Art_Cancro] (Citadel/UX author Art Cancro), with the description field simply repeating the service name and the Reference field left blank — no RFC documents the protocol.
The protocol itself is Citadel's own multithreaded client-server design: a Citadel client connects over TCP 504 to synchronize mail, calendar, address-book, and bulletin-board/room data, and to exchange instant messages, within Citadel/UX and compatible forks. Citadel's own documentation states that although both TCP and UDP were registered with IANA, only the TCP side is actually implemented; local access is handled separately through a Unix domain socket rather than the network port.
The repo's nmap-services extract records an open-frequency of 0.000000 for 504/tcp — a real sampled reading rather than missing data — against roughly 0.000758 for 504/udp, meaning the implemented TCP listener was not observed open in the scan corpus even though the IANA assignment itself is long-standing.
- Exposure
- Internet-facing — Citadel's port 504 protocol exists specifically so remote clients can reach a groupware/BBS server, similar in design intent to other mail-access ports, but connections should still be authenticated and encrypted.
- Malware note
- No malware or trojan association was found for 504/tcp as of an August 2026 search; two generic port-directory sites (SpeedGuide, t1shopper) could not be fetched (HTTP 403 / connection refused) and are not cited for any specific claim.
- Best practice
- Require authenticated, encrypted client connections, keep the underlying Citadel/UX server patched, and firewall or VPN-restrict deployments that are not meant to serve the general public, consistent with general groupware/mail-server hygiene.
- IANA assignment
citadel— description "citadel" (repeats the service name); reference (blank — no RFC cited); assignee[Art_Cancro]; dual-registered 504/tcp + 504/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry citadel 504/tcp, the IANA Service Name and Transport Protocol Port Number Registry citadel 504/udp- Range class
- well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry citadel 504/tcp
- Prevalence
- nmap-services open-frequency 504/tcp = 0.000000 (sampled, not observed open); 504/udp ≈ 0.000758 [Confirmed] — this site's own tooling
- Related ports
- none identified as a paired or companion service [Unknown]
Primary use
native Citadel groupware/BBS client-server protocol for mail, calendar, address-book, room/bulletin-board, and instant-messaging sync; only the TCP side is actually implemented despite dual IANA registration
Other/unofficial uses
none found beyond the Citadel/UX server and its native-protocol clients; no other application has a credible sourced binding to 504/tcp as of an August 2026 search
Security implications
no CVE recorded in the NVD and no malware/trojan association found for 504/tcp as of an August 2026 search
Typically seen on
Citadel/UX groupware and BBS-style servers accepting remote client connections
- Analyst note
- an open 504/tcp is the Citadel groupware protocol's expected remote-client endpoint — legitimate on a known Citadel/UX deployment, but worth confirming given how rarely the assignment appears open in scan data.
About port 504/udp.
Port 504/udp is IANA's mirrored citadel name reservation for the UDP transport, but Citadel's own protocol documentation confirms only the TCP side is actually implemented — Citadel client sessions run over TCP 504, not UDP — so 504/udp carries no confirmed service and should not be assumed to carry Citadel groupware traffic.
IANA registers 504/udp under the service name citadel, with assignee [Art_Cancro] (Art Cancro, the Citadel project's maintainer) and no reference, registration date, or modification date recorded for this entry. The same citadel name is also registered on 504/tcp, confirming a dual TCP/UDP registration for the service.
Citadel is the native client-server protocol for the open-source Citadel/UX groupware server (citserver), covering email, bulletin-board "rooms," calendar, and chat for dedicated Citadel clients. The Citadel project's own documentation describes ordinary client sessions running over TCP; no first-party documentation was found describing a specific UDP-504 use case, so the UDP registration appears to mirror the TCP service name rather than reflect distinct UDP-specific traffic.
- Notable CVE
- none found — no CVE or documented exploit targeting udp/504 turned up in a search as of August 2026, and no botnet or malware campaign specific to this port is recorded.
- Scanning noise
- unsolicited internet-wide scanning of UDP ranges generally includes 504 as routine background noise rather than activity targeted at Citadel specifically.
- IANA assignment
citadel— description "citadel"; assignee [Art_Cancro]; Reference/Registration Date/Modification Date columns blank; dual-registered 504/udp + 504/tcp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry citadel 504/udp- Range class
- well-known/system (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry citadel 504/udp
- Prevalence
- nmap-services open-frequency 504/udp = 0.000758 (~0.076%); 504/tcp = 0 (sampled, not observed open) [Confirmed] — this site's own tooling
- Related ports
- 504/tcp (same
citadeldual registration)
Primary use
Citadel groupware client-server protocol (email, rooms/bulletin boards, calendar, chat) for the Citadel/UX server (citserver); first-party docs describe client sessions running over TCP
Other/unofficial uses
none found beyond the Citadel registration as of an August 2026 search [Unknown]
Security implications
protocol unencrypted by default absent the client-initiated STLS command, per first-party protocol documentation; no CVE or malware association found as of an August 2026 search
Typically seen on
no confirmed deployments — Citadel's own documentation confirms only TCP 504 is implemented, and no application is confirmed to bind 504/udp
- Analyst note
- A responsive 504/udp cannot be attributed to Citadel or any other known application; given the lack of any confirmed listening service, treat direct internet exposure as anomalous and worth investigating rather than assuming Citadel groupware traffic.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| citadel | UDP | — | 0.08% |
| citadel | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.