Network port detail · UDP/TCP

63

Whoispp
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
RFC 1835 explicitly warned that its basic PASSWORD authentication scheme transmits credentials and data unencrypted over the network and is not a secure method. The protocol is Historic and effectively undeployed, so port 63 is not a known active attack vector or high-priority scanner target. No CVEs or dedicated exploit tooling for port 63/whoispp were found in public sources as of mid-2026. An exposed port 63 on modern infrastructure is anomalous and warrants investigation (possible legacy service or misconfiguration).
// analyst note
A responsive port 63 is statistically rare and tied to an obsolete protocol — treat as a legacy WHOIS++ service or misconfiguration and investigate rather than assume normal use.
[ 01 ] — Context

About port 63/tcp.

Updated  ·  Confidence: High

Port 63/tcp is registered with IANA as whoispp, the well-formed canonical service name; a historic alias entry whois++ also exists for the same port and is annotated as "not usable for use with many common service discovery mechanisms," which is why the ++ form was superseded by whoispp. The assignee and contact are both [Rickard_Schoultz], the registration/modification dates and the IANA Reference field are blank (no RFC is cited in the registry), and the port is dual-registered on TCP and UDP. WHOIS++ is a distributed white-pages directory service designed in the early 1990s as an enhanced successor to the original WHOIS protocol on port 43: it added structured information templates, multi-language and character-set support, a richer query syntax, and a distributed indexing scheme built on "centroid" data structures that route queries between cooperating servers. The architecture is specified in RFC 1835 ("Architecture of the WHOIS++ service," August 1995), which the IETF has since reclassified as Historic with no obsoleting successor RFC identified. Reference implementations came from BUNYIP Information Systems, and the ROADS software used by the UK JISC eLib programme exposed academic subject gateways over WHOIS++. The protocol is obsolete today with no actively maintained deployments, so for an analyst a responsive port 63 is anomalous and worth investigating as a legacy service or misconfiguration. RFC 1835 itself warned that its basic PASSWORD authentication scheme transmits credentials and data in cleartext and is not a secure method. No CVEs or dedicated exploit tooling for port 63/whoispp were found in public sources as of mid-2026, and no internet-wide scan data quantifying exposed hosts on port 63/tcp was located.

IANA assignment
whoispp — canonical well-formed service name; historic alias whois++ ("not usable for use with many common service discovery mechanisms"); Reference blank (no RFC cited in registry); assignee/contact [Rickard_Schoultz]; dual-registered 63/tcp + 63/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.csv)
Range class
well-known (0–1023) [Confirmed]
Current status
obsolete / Historic; not deployed in new systems or actively developed; effectively no legitimate modern use [Confirmed] — IETF Datatracker (https://datatracker.ietf.org/doc/rfc1835/)
Related ports
43/tcp (WHOIS, the predecessor protocol)

Primary use

WHOIS++ distributed white-pages directory service — an enhanced successor to WHOIS (port 43) with structured templates, multi-language support, richer query syntax, and centroid-based distributed indexing

[Confirmed] — RFC 1835 (https://www.rfc-editor.org/rfc/rfc1835.html); Wikipedia WHOIS++ (https://en.wikipedia.org/wiki/WHOIS%2B%2B)

Protocol reference

RFC 1835, "Architecture of the WHOIS++ service," August 1995; status Historic (IETF); no obsoleting successor RFC identified. Note: the IANA Reference field for port 63 is blank — RFC 1835 is the architecture document, not an IANA-cited reference

[Confirmed] — RFC 1835 (https://www.rfc-editor.org/rfc/rfc1835.html); IETF Datatracker (https://datatracker.ietf.org/doc/rfc1835/)

Other/historical associations

via-ftp (VIA Systems — FTP & whois++) appears as an alternate historical label in SANS ISC service records; no further VIA Systems documentation found

[Likely] — SANS ISC services (https://isc.sans.edu/services.html)

Common software

BUNYIP Information Systems WHOIS++ reference server (1990s); ROADS software (UK JISC eLib web interface over WHOIS++); no current maintained implementations found

[Likely] — Wikipedia WHOIS++ (https://en.wikipedia.org/wiki/WHOIS%2B%2B)

Security implications

RFC 1835 explicitly warned its basic PASSWORD authentication transmits credentials and data unencrypted and is not secure; because the protocol is historic, port 63 is not a known active attack vector; no CVEs or exploit tooling for whoispp found in public sources as of mid-2026; an exposed port 63 on modern infrastructure is anomalous and warrants investigation

[Confirmed/Likely] — RFC 1835 (https://www.rfc-editor.org/rfc/rfc1835.html)
Scanning exposure
Unknown — no specific internet-wide scan data (Shodan/Censys/SANS ISC) quantifying exposed hosts on port 63/tcp was found in publicly available sources as of 2026-06-19 [Unknown]
Analyst note
A responsive port 63 is statistically rare and tied to an obsolete protocol — treat as a legacy WHOIS++ service or misconfiguration and investigate rather than assume normal use.
[ 02 ] — Context

About port 63/udp.

Updated  ·  Confidence: High

Port 63/udp is registered with IANA as whoispp with a legacy alias whois++, contact Rickard Schoultz, and a blank reference field (dual-registered on TCP and UDP). The IANA registry note explains that whoispp is the well-formed service name IANA assigned as a replacement for the original whois++, and that the whois++ spelling is "now historic, not usable for use with many common service discovery mechanisms." The service is WHOIS++, a 1990s-era distributed white-pages and directory-lookup protocol developed by Bunyip Information Systems as a superset of the original WHOIS (port 43): it added a structured query syntax, internationalization, and multi-server federation in which queries are routed across a mesh of servers using "centroid" index data. WHOIS++ is documented across a small family of IETF RFCs — RFC 1835 (Architecture of the WHOIS++ Service, August 1995), RFC 1913 and RFC 1914 (the index service and how to interact with a WHOIS++ mesh), and RFC 2957/RFC 2958 (the application/whoispp-query and application/whoispp-response content types). None of these RFCs is populated in the IANA Reference column, which is genuinely blank; the registry cites no document for this assignment, so the reference field stays empty rather than being back-filled from the RFC family. The protocol never achieved mainstream adoption and carries IETF Historic status with no known active deployments as of 2026. For an analyst, a responsive port 63 is statistically rare: there is no documented CVE or active exploit campaign specific to it, and internet-wide scan datasets show negligible exposure, so an open port 63 is best treated as an anomaly worth investigating rather than a normal service. Some port-listing databases carry a generic "used by a trojan in the past" caveat while rating current trojan status as none — a database artifact, not evidence of an active threat.

IANA assignment
whoispp — replacement service name for the historic whois++; reference (blank — no RFC cited in IANA registry); contact Rickard Schoultz; dual-registered 63/tcp + 63/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry)
Range class
well-known (0–1023)
Status
IETF Historic; obsolete; no known active deployments as of 2026 [Confirmed] — Wikipedia (WHOIS++)
Related ports
43/tcp (whois), the directory/lookup lineage

Primary use

distributed white-pages / directory lookup (a superset of WHOIS on port 43); queries routed across a mesh of servers via centroid index data

[Confirmed] — Wikipedia (WHOIS++), RFC 1835

Protocol family / RFCs

RFC 1835 (architecture, Aug 1995), RFC 1913, RFC 1914 (index service + mesh interaction), RFC 2957/RFC 2958 (whoispp content types); all IETF Historic

[Confirmed] — IETF Datatracker (RFC 1835/1913/2957/2958). Note: none of these is the IANA Reference value — that column is blank.

Common software

Bunyip Information Systems' original WHOIS++ server implementation (1990s); no widely-used modern software targets this port

[Likely] — Wikipedia (WHOIS++)

Security implications

no documented CVEs or active exploit campaigns specific to port 63/udp; negligible internet-wide scan exposure; port-listing DBs carry a generic historic-trojan caveat but rate current trojan status as none (database artifact, not an active threat)

[Likely/Threat-reported] — auditmypc.com, Gary Kessler bad-ports list

Typically seen on

legacy/experimental directory hosts; otherwise an anomaly / possible decoy

Legacy alias
whois++ — flagged in the registry as "an alias to 'whoispp'" and "now historic, not usable for use with many common service discovery mechanisms" [Confirmed] — IANA registry
Analyst note
An open port 63 is statistically rare and tied to an obsolete protocol — treat as a fingerprinting/anomaly signal and investigate; legitimate active use is unlikely.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
via-ftp UDP VIA Systems - FTP & whois++ 0.04%
via-ftp TCP whoispp 0.00%
IANA name
whoispp
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.