55
Summary
- // if you see it open
- SANS Internet Storm Center rates port 55 at threat level GREEN (lowest) with no CVEs and no documented exploits for the ISI-GL service. The registered protocol is fully obsolete and has no active exploitation surface. Observed inbound activity is low-volume background scanning consistent with mass probing of low-numbered ports rather than targeted traffic. A 2004 SANS ISC community comment historically associated TCP/55 with credential tunneling on machines compromised by the SucKIT Linux kernel rootkit (forwarding TTY-sniffed credentials) — this is community-sourced, specific to the early-2000s era, and not independently corroborated in this research (confidence: Likely). An open port 55 is more likely a scanner artifact, decoy, or mislabeled service than a genuine ISI-GL endpoint; block inbound port 55 on any host not deliberately running legacy software.
- // analyst note
- An open port 55 is statistically rare and almost certainly not a live ISI-GL service — treat as a scanner artifact, decoy, or mislabeled/non-standard local service and investigate; legitimate use is unlikely.
About port 55/tcp.
Port 55/tcp is registered with IANA as isi-gl with the description "ISI Graphics Language," a blank assignee and contact, and a blank reference field (dual-registered on TCP and UDP — 55/tcp and 55/udp carry identical registry rows, both with every metadata column empty). ISI Graphics Language (ISI-GL) was an early protocol associated with USC's Information Sciences Institute (ISI), the ARPANET-era research center; the assignment dates to the period when low-numbered ports were handed out for experimental and research display protocols, and the registry preserves only the service name and description. No RFC, assignee, contact, or registration date is recorded by IANA for this entry — those columns are genuinely absent from the registry record, not merely unknown to this research. The protocol concerned the transfer of graphical display commands across networked systems and has no known active implementation; it predates and was effectively displaced by general-purpose remote-display protocols such as the X Window System (X11), and later RDP and VNC, so it is best treated as obsolete. For an analyst, port 55 is overwhelmingly a legacy curiosity: there are no documented production deployments of ISI-GL, SANS Internet Storm Center currently rates the port GREEN (lowest threat level), and observed inbound traffic is low-volume background scanning consistent with mass internet probing of low-numbered ports rather than targeted activity. One historical caveat is worth recording honestly: a 2004 SANS ISC community comment associated TCP/55 with credential tunneling on machines compromised by the SucKIT Linux kernel rootkit, the implication being that credentials captured by the rootkit's TTY sniffer were forwarded over this port — that claim is community-sourced rather than from a vendor advisory, period-specific to the early 2000s, and was not independently corroborated in this pass, so it is tagged Likely. A responsive port 55 today is therefore far more likely to be a scanner artifact, a decoy, or a non-standard local use than a genuine ISI-GL service, and inbound port 55 should simply be blocked on any host not deliberately running legacy software.
- IANA assignment
isi-gl— "ISI Graphics Language"; reference (blank — no RFC cited in IANA registry); assignee and contact both blank in the registry record; dual-registered 55/tcp + 55/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry lines 118–119); https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml- Range class
- well-known (0–1023) [Confirmed]
- Registration date
- Unknown — IANA records no registration date for this entry (column blank in source) and no authoritative source documents when port 55 was first assigned [Unknown] — the IANA Service Name and Transport Protocol Port Number Registry line 118 (blank column)
- Status
- legacy / obsolete — no known active ISI-GL deployments; effectively superseded by general-purpose remote-display protocols (X11, and later RDP/VNC) [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml ; https://whatportis.com/ports/55_isi-graphics-language-isi-gl
- Related ports
- the adjacent IANA block is dominated by the XNS cluster — 52 (xns-time), 54 (xns-ch / XNS Clearinghouse), 56 (xns-auth), 58 (xns-mail) — and 53 (domain/DNS); none of these are related to ISI-GL, which sits in the same numeric range only by coincidence[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
Primary use
early networked graphical-display command transfer protocol associated with USC's Information Sciences Institute (ISI); ARPANET-era research computing. No current primary use [Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml ; https://whatportis.com/ports/55_isi-graphics-language-isi-gl
Common software
none documented — the protocol predates widespread commercial software and no implementations are recorded in publicly available sources
Security implications
SANS ISC threat level GREEN (lowest); no CVEs and no documented exploits for the ISI-GL service; the registered protocol has no active exploitation surface due to complete obsolescence. A 2004 SANS ISC community note associated TCP/55 with credential tunneling on SucKIT-rootkit-compromised Linux hosts — community-sourced, era-specific, and not independently corroborated here
Exposure / scanning
SANS ISC records scattered inbound scan sources hitting port 55 (e.g. clustered/automated source ranges), consistent with mass internet scanning of low-numbered ports rather than targeted ISI-GL exploitation; no significant authenticated Shodan exposure data was retrievable for this specific port
- RFC reference
- none — the IANA registry cites no RFC for this assignment; ISI-GL was never formally standardized via RFC [Confirmed] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xml
- Analyst note
- An open port 55 is statistically rare and almost certainly not a live ISI-GL service — treat as a scanner artifact, decoy, or mislabeled/non-standard local service and investigate; legitimate use is unlikely.
About port 55/udp.
Port 55/udp is registered with IANA as isi-gl with the description "ISI Graphics Language," and every other column in the registry — assignee, contact, registration date, modification date, and reference — is blank (dual-registered on TCP and UDP; 55/tcp carries the identical name and description). ISI Graphics Language (ISI-GL) traces to the USC Information Sciences Institute (ISI), the ARPANET-era research home that also produced much of the early Internet protocol corpus; the service name describes an experimental scheme for moving vector-style graphical data — rendering commands and display primitives — between research hosts, predating the modern remote-graphics stack (X11, RDP, VNC). No RFC was ever published for it, which is consistent with the blank IANA reference field, and no living software implementation has been traced in current sources, so the protocol is effectively dead. For an analyst the practical takeaway is that legitimate 55/udp traffic is essentially never seen today. SANS Internet Storm Center rates port 55 at threat level green (low activity), and its telemetry shows only sparse, dispersed probing rather than any concentrated campaign. The one historical security note worth recording is a 2004 SANS ISC community report associating port 55 with credential exfiltration on Linux hosts compromised by the SucKIT loadable-kernel-module rootkit; because SucKIT can hide an arbitrary TCP/UDP socket, the choice of port 55 was opportunistic rather than protocol-driven, and this is a dated low-confidence indicator, not a current threat signature. No CVE or recent threat-actor activity is specifically tied to 55/udp in available sources. Because the legacy protocol has no encryption, authentication, or error handling and no software runs on it, the real attack surface is negligible unless a process is deliberately bound to the port after a compromise — which is exactly why an unexpected listener on 55/udp is worth investigating rather than dismissing.
- IANA assignment
isi-gl— "ISI Graphics Language"; reference (blank — no RFC cited in IANA registry); assignee blank; dual-registered 55/tcp + 55/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (local cache the IANA Service Name and Transport Protocol Port Number Registry line 119; both angles agree)- Range class
- well-known (0–1023) [Confirmed]
- Prevalence
- SANS ISC threat level green (low activity); only sparse, dispersed probing observed — no specific nmap-services open-frequency figure available in local registries (not asserted) [Likely] — isc.sans.edu/data/port/55
- Registration date
- Unknown — IANA registry carries no registration or modification date for this entry; not attributed to any source [Unknown] — the IANA Service Name and Transport Protocol Port Number Registry (blank columns)
- Related ports
- 55/tcp (identical dual registration); contrast modern remote-graphics ports (X11 6000–6063, RDP 3389, VNC 5900)
Primary use
experimental ISI Graphics Language — vector/graphical data transfer between ARPANET-era research hosts; no RFC; effectively obsolete
Other/unofficial uses
none documented; superseded for remote graphics by X11, RDP, and VNC
Security implications
no encryption/authentication/error handling in the legacy protocol, but no live software runs on it, so practical attack surface is negligible; an unexpected bound listener post-compromise is the scenario to investigate
Common software
Unknown — no active implementation documented in available sources [Unknown]
Malware associations
historical only — a 2004 SANS ISC community note tied port 55 to credential exfiltration via the SucKIT LKM rootkit (opportunistic port use, not protocol-bound); dated and low-confidence, no current campaign or CVE identified
Typically seen on
nothing in normal operation; an open 55/udp is an anomaly worth investigating as a decoy or backdoor
- Analyst note
- Legitimate 55/udp is essentially never seen today. Treat a responsive port as an anomaly — possible post-compromise listener, decoy, or backdoor — not a normal service.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| isi-gl | UDP | ISI Graphics Language | 0.05% |
| isi-gl | TCP | ISI Graphics Language | 0.01% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.