518
Summary
- // if you see it open
- Same obsolescence as talk: no encryption or authentication; negligible modern footprint.
- // analyst note
- An open 518 indicates a legacy ntalk daemon; treat as cruft and disable.
About port 518.
Port 518/tcp is registered with IANA as ntalk with a blank description field (the service name is registered with no description string on both 518/tcp and 518/udp) and blank assignee, contact, and reference fields. It is ntalk (ntalkd / in.ntalkd), the BSD 4.3 revision of the talk protocol with an incompatible, changed message format — the talk and ntalk protocols do not interoperate — implementing the same real-time two-user chat model. Like the original talk, it is primarily a UDP service: client-to-ntalkd control runs over UDP 518, with a separate data path for the conversation, and ALG documentation for the talk family notes it uses UDP 517 and 518 for control while opening both TCP and UDP gates for the session. The IANA reference field is blank, and the registry carries no description for this entry. Security-wise it shares the same obsolescence as talk — no encryption or authentication and a negligible modern footprint. For an analyst, an open 518 indicates a legacy ntalk daemon and should be treated as cruft and disabled.
- IANA assignment
ntalk— (description blank in registry); reference (blank — no RFC cited in IANA registry); assignee/contact blank; dual-registered 518/tcp + 518/udp (UDP carries the control) [IANA-assigned] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023)
- Prevalence
- nmap-services open-frequency 518/tcp ~0.000013 (de-facto) [Well-established] — nmap-services file
- Related ports
- 517 (talk — the original, incompatible protocol)
Primary use
real-time two-user chat (ntalkd, the BSD 4.3 revised talk) [Well-established]
Other/unofficial uses
none today [Well-established]
Security implications
obsolete; no encryption/auth; negligible modern footprint [Well-established]
Typically seen on
old Unix running in.ntalkd
- Analyst note
- An open 518 indicates a legacy ntalk daemon; treat as cruft and disable.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| ntalk | UDP | (talkd) | 2.22% |
| ntalk | TCP | (talkd) | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.