564
Summary
- // if you see it open
- 9P/Styx has no built-in authentication or encryption by default, so an internet-exposed instance can allow unauthenticated remote filesystem access; it should be restricted to trusted Plan 9 networks or tunneled. SANS ISC records only routine low-volume background scanning against this port, with the site's overall threat indicator at green (no elevated activity), as of a September 2026 check, and no CVE or malware/trojan association was found in the sources checked.
About port 564/tcp.
Port 564/tcp carries 9pfs, the Plan 9 file service that implements the 9P (Styx) distributed-filesystem protocol; it should stay internal-only rather than be exposed to the public internet.
IANA registers the port under the service name 9pfs, described as "plan 9 file service," dual-registered on both TCP and UDP with identical metadata. No RFC or other reference document backs the assignment, and no assignee is listed.
9P (also called Styx) is the network protocol used by Plan 9 from Bell Labs to connect file servers, terminals, and CPU servers over a network. The Plan 9 project's own wiki documents disk file servers such as fossil(4) listening on this port for TCP boot or general-purpose storage, and independent third-party 9P client/server implementations such as v9fs and rust-9p can be configured to use it, though this is a convention rather than a hard requirement.
SANS Internet Storm Center records only routine, low-volume background scanning against this port, with the site's overall threat indicator at green (no elevated activity) as of a September 2026 check. No CVE or malware/trojan association was found in the sources checked as of that date.
- Exposure
- Internal-only — 9P/Styx has no built-in authentication or encryption by default, so an internet-reachable instance risks unauthenticated remote filesystem access; restrict it to trusted Plan 9 networks or a tunnel.
- Scanning activity
- SANS ISC shows only routine low-volume background scanning, with the site's overall threat indicator at green (no elevated activity), as of a September 2026 check (isc.sans.edu/data/port/564).
- CVE / malware
- No CVE or malware/trojan association found in the sources checked as of September 2026.
- Registration gap
- No RFC or reference document is associated with the 9pfs registration; the field is blank in the IANA registry, not omitted here.
- Service name
- 9pfs — [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry 9pfs 564/tcp)
- IANA reference
- none listed (blank) — [Confirmed] (iana.org/assignments/service-names-port-numbers)
Protocol in practice
9P / Styx, the Plan 9 distributed-filesystem protocol — [Confirmed] (en.wikipedia.org/wiki/9P_(protocol))
- Description
- plan 9 file service — [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry 9pfs 564/tcp)
- Transport
- TCP, dual-registered with UDP (9pfs 564/udp) — [Confirmed] (the IANA Service Name and Transport Protocol Port Number Registry)
- Assignee
- none listed — [Confirmed] (iana.org/assignments/service-names-port-numbers)
- Community-observed usage
- fossil(4) disk file server documented listening on 564 for TCP boot / storage — [Likely] (9p.io/wiki/plan9/9p_services_using_srv,_listen,_exportfs,_import)
- Community-observed usage
- third-party 9P implementations (e.g. v9fs, rust-9p) configurable to use this port — [Likely] (github.com/pfpacket/rust-9p)
- Scanning activity
- routine low-volume background scanning only, with the site's overall threat indicator at green (no elevated activity), as of September 2026 — [Confirmed] (isc.sans.edu/data/port/564)
- CVE / malware association
- none found as of a September 2026 search — [Unknown]
About port 564/udp.
Port 564/udp carries 9pfs, the Plan 9 file service — the 9P filesystem-export protocol used by the Plan 9 from Bell Labs operating system and its userspace port, Plan 9 from User Space (plan9port); it should stay internal-only rather than be exposed to the public internet.
IANA's service-names-port-numbers registry lists 9pfs on both 564/tcp and 564/udp, with the assignee and reference columns left blank and no RFC cited. Two independent secondary port-tracking sites, SANS Internet Storm Center and SpeedGuide, corroborate the same service name and dual registration.
The site's built-in port dataset (this site's own tooling, derived from nmap-services) records an open-frequency of 0.0527% for 564/udp and 0.0013% for 564/tcp — a real sampled measurement showing the port is rarely found open in general internet scanning, consistent with a niche protocol tied to a research operating system rather than mainstream infrastructure.
No third-party application beyond the Plan 9 ecosystem was found documented as using this port, and no malware family, botnet, or CVE is recorded as associated with it as of a September 2026 search. SANS ISC's port-activity dashboard shows only low-volume, scattered background scanning, consistent with routine internet-wide scan noise rather than a targeted campaign.
- Exposure
- 9P is a remote filesystem-export protocol without the access-control hardening typical of modern remote-access services, so an internet-facing instance should be treated as internal-only, similar to SMB or NFS.
- Scanning activity
- SANS Internet Storm Center's port-activity dashboard shows only low-volume, scattered background scanning on port 564 (single-digit hits per source) as of an early-September 2026 check, consistent with routine internet-wide scan noise rather than a targeted campaign (https://isc.sans.edu/data/port/564).
- Malware associations
- No malware family, botnet, or CVE is recorded as associated with port 564 as of a September 2026 search.
- Common software
- No credible sighting of third-party software beyond the Plan 9 ecosystem (the Plan 9 kernel's 9P client/server and Plan 9 from User Space / plan9port) was found using this port.
- Service name
- 9pfs ("plan 9 file service") — [Confirmed] the IANA Service Name and Transport Protocol Port Number Registry 9pfs 564/udp
- Dual registration
- Both 564/tcp and 564/udp are registered to the same service — [Confirmed] the IANA Service Name and Transport Protocol Port Number Registry 9pfs 564/tcp; 9pfs 564/udp
- IANA reference/RFC
- Unknown — the registry's reference column is blank for this entry — [Confirmed] the IANA Service Name and Transport Protocol Port Number Registry 9pfs 564/udp
Primary use
9P/Plan 9 filesystem protocol, used by Plan 9 from Bell Labs and Plan 9 from User Space (plan9port) to export/mount remote filesystems — [Likely] https://en.wikipedia.org/wiki/9P_(protocol), https://9p.io/wiki/plan9/9p_services_using_srv,_listen,_exportfs,_import/index.html
Malware/CVE association
None found as of a September 2026 search — [Unknown]
- Port/Transport
- 564/udp — [Confirmed] the IANA Service Name and Transport Protocol Port Number Registry 9pfs 564/udp
- Assignee
- Unknown — the registry's assignee field is blank — [Confirmed] the IANA Service Name and Transport Protocol Port Number Registry 9pfs 564/udp
- Open-frequency (prevalence)
- 0.0527% for 564/udp (0.0013% for 564/tcp) per the site's built-in port dataset — [Confirmed] this site's own tooling
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| 9pfs | UDP | plan 9 file service | 0.05% |
| 9pfs | TCP | plan 9 file service | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.