Network port detail · UDP/TCP

59

"any private file service"
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Negligible internet exposure. Not in Nmap's default top-1000 ports, and not seen in Shodan top-port lists or SANS ISC high-activity digests. The current IANA entry is only the 'any private file service' placeholder, so port 59 is not a recognized attack surface — any traffic should be treated as anomalous (scanning, misconfiguration, a custom/obscure private application, or backdoor activity). The one historical note is the DMSetup trojan/backdoor, listed against TCP port 59 in security port-reference databases as an early-2000s C2 port; it is historical and low-prevalence (no recent CVE or current-threat reporting found in 2024–2026 searches, and a past listing does not imply current infection). Recommended posture: block inbound and outbound by default.
// analyst note
Treat an open port 59 as anomalous. There is no legitimate modern listener and no protocol history; IANA records only a private-use placeholder, and the sole security signal is the historical DMSetup trojan listing.
[ 01 ] — Context

About port 59/tcp.

Updated  ·  Confidence: High

Port 59/tcp is registered with IANA with the description "any private file service," assignee and contact Jon Postel, a blank service-name field (no short IANA service name is assigned), and a blank reference field; it is dual-registered on TCP and UDP with identical values. The "any private file service" wording is the same private-use placeholder language IANA applies to the neighboring reservation "any private terminal access" on 57; port 58 by contrast carries the registered service XNS Mail (service name xns-mail, assignee Susie Armstrong) rather than a Postel placeholder — so the registration deliberately names no published, interoperable protocol and points to no RFC. Unlike port 57, which at least carried the obsolete Mail Transfer Protocol historically, port 59 has no specific protocol lineage at all: it was set aside as a generic reservation for unspecified private file-transfer use and was never bound to a concrete specification. In practice the port sees essentially no legitimate traffic. Nmap's nmap-services file records an open-frequency of about 0.000088 for 59/tcp (one of the lowest values in the System Ports range) and about 0.000478 for 59/udp; neither figure represents meaningful real-world deployment, and the port is not part of Nmap's default top-1000 set. The one security note worth recording is a historical malware association: security port-reference databases (SANS ISC, AuditMyPC) list the early-2000s trojan/backdoor "DMSetup" against TCP port 59, which it reportedly used for command-and-control. That association is historical and low-prevalence — no recent CVE or current-threat reporting for DMSetup surfaced in 2024–2026 searches, and AuditMyPC explicitly cautions that a past listing does not imply current infection. For an analyst, port 59 is therefore best treated as a port with no legitimate modern listener: any observed traffic on 59/tcp is anomalous and worth investigating (scanning, misconfiguration, a custom private application, or — given the DMSetup history — possible backdoor activity), and the recommended firewall posture is to block it inbound and outbound by default.

IANA assignment
service name blank (no short name registered) — description "any private file service"; reference (blank — none cited in IANA registry); assignee/contact Jon Postel; dual-registered 59/tcp + 59/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry lines 126–127; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv
Range class
well-known (0–1023) [Confirmed]
Prevalence
negligible — nmap-services open-frequency 59/tcp ≈ 0.000088 (among the lowest in the System Ports range); 59/udp ≈ 0.000478; neither represents meaningful real-world usage, and 59 is not in Nmap's default top-1000 set [Likely] — https://svn.nmap.org/nmap/nmap-services
Registration date
Unknown — no registration or modification date is published by IANA for port 59; third-party "date registered" values are database artifacts, not authoritative [Unknown] — the IANA Service Name and Transport Protocol Port Number Registry line 126 (date columns blank)
Related ports
the adjacent Jon Postel private-use placeholders 57 ("any private terminal access") and 58 (registry value "XNS Mail" / placeholder lineage); contrast 20/21 (FTP) as the standard file-transfer service port 59 was nominally reserved near

Primary use

none currently published — registry value is the placeholder "any private file service," i.e. set aside for unspecified private file-transfer use rather than bound to an interoperable service; no RFC defines a concrete protocol for it

[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 126

Common software

Unknown — no known modern software actively binds 59/tcp for legitimate use; the IANA reservation corresponds to no widely deployed application or daemon [Unknown]

Malware associations

DMSetup — an early-2000s-era trojan/backdoor listed by security port-reference databases as having used TCP port 59 for command-and-control. Historical and low-prevalence; no recent CVE or current-threat reporting found in 2024–2026 searches, and a past listing does not imply current infection

[Likely] — https://isc.sans.edu/data/port/59 ; https://www.auditmypc.com/tcp-port-59.asp

Security implications

negligible internet exposure; not in Nmap's default top-1000 ports; not seen in Shodan top-port lists or SANS ISC high-activity digests. Because the current registration is only the "any private file service" placeholder and there is no legitimate modern service, port 59 is not a recognized attack surface — any traffic is anomalous and worth investigating (scan, misconfiguration, custom private app, or DMSetup-style backdoor activity given the historical association)

[Likely] — https://isc.sans.edu/data/port/59 ; https://svn.nmap.org/nmap/nmap-services

Typically seen on

nothing in modern use; an open 59/tcp is an anomaly

Historical use
none specific — unlike port 57 (obsolete MTP), port 59 has no documented protocol lineage; it is a generic Jon Postel-era private-use reservation, a sibling of "any private terminal access" (57); port 58 is the registered XNS Mail service (xns-mail, assignee Susie Armstrong), not a Postel placeholder
[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry lines 122, 124–127
Common-tool label
Nmap (nmap-services) and SANS ISC use the short label "priv-file" for port 59; this is a tool convention, not an official IANA service name (the IANA service-name field is blank) [Likely] — https://svn.nmap.org/nmap/nmap-services ; https://isc.sans.edu/services.html
Security posture
block inbound and outbound on perimeter firewalls by default; no legitimate modern service requires this port externally [Likely] — https://isc.sans.edu/data/port/59 ; https://www.auditmypc.com/tcp-port-59.asp
Analyst note
Treat an open port 59 as anomalous. There is no legitimate modern listener and no protocol history; IANA records only a private-use placeholder, and the sole security signal is the historical DMSetup trojan listing.
[ 02 ] — Context

About port 59/udp.

Updated  ·  Confidence: Medium

Port 59/udp is registered in the IANA Service Name and Transport Protocol Port Number Registry as "any private file service," with no formal short service name, assignee and contact both Jon Postel, and a blank Reference column. It is a generic placeholder rather than the registration of a specific protocol: the same description, assignee, and blank-reference metadata appear on 59/tcp as well, so the number is dual-registered across both transports without naming any concrete software. Because no standardized protocol is defined for the port, there is no documented, widely deployed production service that uses 59/udp; any legitimate use would be private/proprietary by definition, which is exactly what the "any private file service" wording reserves for. The only named association in public threat references is on the TCP side: the legacy early-2000s Windows mIRC trojan DM.Setup (DMSetup), which modified mIRC configuration to enable unauthorized DCC file transfers and has historically been linked to port 59 — that is a TCP-side artifact, not a UDP service, and has no current significant prevalence. SANS Internet Storm Center rates port 59 green (low threat) as of mid-2026, with scanning telemetry that combines TCP and UDP and shows generally single-digit daily counts apart from occasional outlier spikes (for example a single source on 2026-06-18 generating 51 scans). For an analyst the practical reading is that 59/udp carries no defined service, so any traffic observed on it in a monitored environment should be treated as anomalous and investigated rather than mapped to a known application.

IANA assignment
"any private file service" — no formal short service name; Reference (blank — none cited in IANA registry); assignee/contact Jon Postel; dual-registered 59/tcp + 59/udp with identical metadata [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry line 127; 59/tcp on line 126)
Range class
well-known (0–1023) [Confirmed] — IANA registry
Registration / modification date
blank in IANA source — recorded as Unknown, not fabricated [Confirmed] — IANA registry (CSV columns blank)
Related ports
59/tcp (identical IANA placeholder registration)

Primary use

none standardized; generic placeholder reserving the number for private/proprietary file service use; no documented widespread UDP software

[Confirmed] — IANA registry

Other/unofficial uses

none identified for UDP; on TCP, legacy association with the DM.Setup (DMSetup) mIRC trojan (early-2000s Windows, unauthorized DCC file transfer)

[Likely] — F-Secure DMSetup description; EventTracker port 59 reference

Security implications

SANS ISC threat level green (low) mid-2026; very low scanning volume (single-digit daily, occasional outlier spike); no CVEs or active exploits specific to 59/udp in available sources; any 59/udp traffic should be treated as anomalous

[Likely] — SANS ISC port 59 page

Exposure / scanning notes

ISC telemetry logs TCP+UDP for port 59 together; sporadic low-volume scans, e.g. a single source (85.217.149.25) generated 51 scans on 2026-06-18 as an outlier

[Likely] — SANS ISC port 59 page

Typically seen on

nothing legitimate; an open/responsive 59/udp is an anomaly worth investigating

Analyst note
No defined service means no expected baseline — investigate any 59/udp traffic as anomalous rather than mapping it to a known application.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
priv-file UDP any private file service 0.05%
priv-file TCP any private file service 0.01%
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.