511
Summary
- // if you see it open
- No CVE, malware/trojan association, or scanning/honeypot data was found for port 511 as of an August 2026 search. auditmypc.com was checked but returned only generic tool-interface text, not a port-511-specific verdict. The registered name is likely tied to PassGo Technologies' identity-authentication software line, but no vendor documentation confirms the port binding, so exposure risk cannot be curated with confidence.
- // analyst note
- A live 511/tcp responder has no confirmed legitimate driver in current use and no known threat lineage — log and investigate rather than assume either benign default or attack indicator.
About port 511/tcp.
Port 511/tcp is IANA-registered under the service name "passgo," but no public protocol specification or documented real-world deployment was found, so it should not be expected on the public internet — treat a live 511/tcp responder as unusual and worth investigating rather than as a normal service.
The IANA registry lists 511/tcp (and the paired 511/udp) as "passgo," description "PassGo," assignee and contact [John_Rainford], with a blank Reference column and no registration or modification date recorded. Both transports carry identical registrant data.
The name most plausibly ties to PassGo Technologies, a UK identity-authentication software vendor whose PASSGO trademark covers "computer application software for authenticating user identity." No vendor protocol document, blog post, or forum thread was found confirming that this software actually listens on port 511, so the link is treated as likely rather than confirmed.
Measured prevalence from the repo's nmap-services-derived data is low: open-frequency 511/tcp ≈ 0.000038 (~0.004%) and 511/udp ≈ 0.00061 (~0.061%). Neither figure indicates common deployment, consistent with a niche or largely discontinued product.
- Exposure
- No protocol specification or documented deployment was found for 511/tcp, so there is no curated basis to place it in a specific exposure category — treated as Unknown rather than guessed.
- Malware/trojan association
- auditmypc.com was checked but returned only generic tool-interface text with no port-511-specific verdict; no other source associates port 511 with a named trojan or malware family as of an August 2026 search.
- CVE
- No CVE is recorded as associated with port 511 as of an August 2026 search.
- Scanning/exposure data
- No port-511-specific scanning-prevalence or honeypot data (Shodan counts, CISA/SANS advisories) surfaced as of August 2026.
- IANA assignment
passgo— "PassGo"; reference (blank); assignee/contact[John_Rainford]; dual-registered 511/tcp + 511/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry passgo 511/tcp- Range class
- system/registered (well-known, 0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry passgo 511/tcp
- Prevalence
- nmap-services open-frequency 511/tcp ≈ 0.000038 (~0.004%); 511/udp ≈ 0.00061 (~0.061%) [Confirmed] — this site's own tooling
- Related ports
- other IANA-registered small/legacy authentication-adjacent services; contrast with well-documented auth ports (e.g. 389 LDAP, 636 LDAPS)
Primary use
registered service name "passgo" (PassGo); no RFC or technical reference cited in the registry
Other/unofficial uses
none documented in this search [Unknown]
Security implications
no CVE, no malware/trojan association, and no scanning/honeypot data found as of an August 2026 search [Unknown, sourced negative]
Typically seen on
no documented deployment pattern found in this search [Unknown]
- Likely origin
- PassGo Technologies (South Somerset, UK), identity-authentication software vendor; PASSGO trademark covers "computer application software for authenticating user identity" [Likely] — https://trademarks.justia.com/865/20/passgo-86520645.html
- Analyst note
- A live 511/tcp responder has no confirmed legitimate driver in current use and no known threat lineage — log and investigate rather than assume either benign default or attack indicator.
About port 511/udp.
Port 511/udp is registered to IANA's passgo service name, likely tied to PassGo Technologies' identity/access-management software, but no source confirms what actually listens on it in practice, so whether it belongs on the public internet is unresolved rather than settled either way.
The IANA registry row lists service name passgo, description "PassGo," dual-registered on 511/tcp and 511/udp, contact/registrant John Rainford, and a blank Reference field — there is no RFC behind the assignment. The row itself binds only a description string and a personal registrant handle, not a company name.
Coverage of Quest Software's December 2007 acquisition of PassGo Technologies places a John Rainford as PassGo personnel who moved into a VP role at Quest afterward, which supports — without formally confirming — that the registrant is connected to PassGo Technologies. No vendor protocol document, blog post, or forum thread was found confirming that PassGo (or later Quest) software actually listens on port 511/udp.
Measured prevalence from the nmap-services frequency data puts 511/udp at an open-frequency of 0.00061 (~0.061%), versus 0.000038 (~0.004%) for 511/tcp — both low, consistent with a niche or largely discontinued product rather than a commonly-scanned or commonly-open port.
No credible source ties 511/udp to a specific malware or trojan family, or to documented internet-wide scanning or exposure telemetry, as of an August 2026 search. Several older trojan-port-list aggregators attribute a "T0rn Rootkit" to port 511, but primary technical write-ups on the t0rn/tornkit rootkit place it on TCP 47017, and the related Lion-worm variant on TCP 27374 — neither source corroborates a port-511 tie, so the aggregator claim is not treated as credible.
- Notable CVE
- none found tied to 511/udp or the PassGo product line as of an August 2026 search.
- Malware/trojan association
- no credible source associates 511/udp with a named malware or trojan family as of an August 2026 search; a "T0rn Rootkit" attribution appearing in several mutually-copying trojan-port-list aggregators is contradicted by primary t0rn/tornkit documentation, which places that rootkit on TCP 47017 (and the related Lion-worm variant on TCP 27374).
- Scanning/exposure telemetry
- no dated scanning-telemetry or honeypot source specific to 511/udp was found as of an August 2026 search.
- Vendor status
- PassGo Technologies was acquired by Quest Software in December 2007; the original PassGo product line is not actively marketed under that name today.
- IANA assignment
passgo— "PassGo"; reference (blank — no RFC cited in IANA registry); assignee John Rainford; dual-registered 511/tcp + 511/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry passgo 511/udp- Range class
- system/well-known (0–1023) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry passgo 511/udp
- Prevalence
- nmap-services open-frequency 511/udp ≈ 0.00061 (~0.061%); 511/tcp ≈ 0.000038 (~0.004%) [Confirmed] — this site's own tooling
- Related ports
- 511/tcp (dual registration of the same
passgoservice) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry passgo 511/tcp
Primary use
identity/access-management service likely tied to PassGo Technologies' privilege-management and single sign-on software; the registry row itself binds only a description string and a personal registrant handle, not the company [Likely] — the IANA Service Name and Transport Protocol Port Number Registry passgo 511/udp; https://www.itjungle.com/2007/12/10/tfh121007-story07-3/
Other/unofficial uses
none documented beyond the possible tie to the original PassGo product line
Security implications
no CVE, malware association, or scanning telemetry found specific to 511/udp; a trojan-port-list "T0rn Rootkit" attribution to port 511 is uncorroborated by primary t0rn/tornkit documentation, which cites TCP 47017
Typically seen on
not documented; no vendor or community source confirms an environment where 511/udp is actually open [Unknown]
- Analyst note
- An open port 511/udp is uncommon and its registration is only loosely tied to a historical enterprise identity-management vendor; treat an unexpected sighting as worth investigating rather than assuming a live deployment of any specific product.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| passgo | UDP | — | 0.06% |
| passgo | TCP | — | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.