Network port detail · UDP/TCP

65

Tacacs-ds
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No known malware or trojan associations. tacacs-ds is a legacy/dormant IANA assignment superseded by TACACS+ on 49/tcp (RFC 8907, September 2020). No current software is documented binding 65/tcp for tacacs-ds, so an open port 65 on modern infrastructure is most likely a misconfigured or unrelated listener rather than a genuine tacacs-ds service. Blocking 65/tcp inbound is standard and safe.
// analyst note
tacacs-ds is a legacy IANA entry with no verifiable active software. Treat a responsive port 65 as anomalous; do not assume a genuine tacacs-ds listener.
[ 01 ] — Context

About port 65/tcp.

Updated  ·  Confidence: High

Port 65/tcp is registered with IANA as tacacs-ds with the description "TACACS-Database Service," assignee Kathy Huber, and a blank reference field; it is dual-registered on both TCP and UDP with identical metadata. The name belongs to the original TACACS (Terminal Access Controller Access-Control System) family — an early AAA (authentication, authorization, accounting) protocol developed at BBN Technologies in the 1980s for ARPANET/MILNET terminal-server administration. The primary TACACS port is 49/tcp (documented in RFC 1492); port 65 was a companion registration for a database-service component of that original protocol rather than a port carrying its own standalone RFC. In practice the assignment is a legacy artifact: the original TACACS and its database-service adjunct were superseded first by Cisco's Extended TACACS (XTACACS) and then by TACACS+ (RFC 8907, published September 2020), which uses port 49/tcp exclusively and does not touch port 65. For an analyst, port 65 matters mainly as one of the dormant low-number IANA assignments: no current production software is documented binding to it for tacacs-ds, internet exposure is very low, and no known malware family or mass-scanning campaign targets it. An open 65/tcp on modern infrastructure is therefore more likely a misconfigured or unrelated listener than a genuine tacacs-ds service, and blocking it inbound is standard and safe. The IANA reference field is blank — no RFC is cited in the registry for this entry, and that blank is recorded honestly rather than back-filled.

IANA assignment
tacacs-ds — "TACACS-Database Service"; reference (blank — no RFC cited in IANA registry); assignee Kathy Huber; dual-registered 65/tcp + 65/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry lines 146–147)
Range class
well-known (0–1023)
Prevalence
very low internet exposure; no documented mass-scanning campaigns or significant Shodan patterns for port 65 [Likely] — speedguide.net/port.php?port=65, auditmypc.com/tcp-port-65.asp
Related ports
49/tcp (TACACS / TACACS+, primary AAA port)

Primary use

legacy database-service component of the original TACACS AAA protocol; companion to the primary TACACS port 49/tcp (RFC 1492)

[Likely] — IANA registry; en.wikipedia.org/wiki/TACACS

Other/unofficial uses

none documented; no current software is known to bind 65/tcp for tacacs-ds [Unknown]

Security implications

no known malware or trojan associations; legacy/dormant assignment superseded by TACACS+ on 49/tcp (RFC 8907, 2020); an open 65/tcp on modern hosts is most likely a misconfigured or unrelated service; blocking inbound is standard and safe

[Likely] — securew2.com TACACS overview; IANA registry

Typically seen on

no documented active deployments; an open 65/tcp is an anomaly worth investigating

Analyst note
tacacs-ds is a legacy IANA entry with no verifiable active software. Treat a responsive port 65 as anomalous; do not assume a genuine tacacs-ds listener.
[ 02 ] — Context

About port 65/udp.

Updated  ·  Confidence: Medium

Port 65/udp is registered with IANA as tacacs-ds with the description "TACACS-Database Service," assignee Kathy Huber, and a blank reference field (dual-registered on TCP and UDP). The name places it in the TACACS (Terminal Access Controller Access-Control System) family — the centralized AAA (Authentication, Authorization, Accounting) lineage that originated with the original RFC 1492 TACACS and evolved through XTACACS into Cisco's TACACS+. The "-ds" suffix marks this as a database-service variant, intended for centralized credential/policy database lookups rather than the interactive AAA exchange itself. In practice this is a legacy registration: the IANA entry carries no RFC reference, no registration or modification date, and no service code, and no current TACACS implementation documentation references port 65 in either transport. The live ecosystem is built almost entirely on TACACS+, which runs on TCP/49 and is the de-facto standard in modern enterprise gear (Cisco IOS, Oracle Session Border Controller, and most network-OS AAA stacks). For an analyst, port 65/udp is therefore best treated as a near-dormant assignment: it does not appear on common scanning watchlists, Shodan top-port lists, or published internet-exposure studies, and no CVEs or malware/trojan associations were identified for it. A responsive 65/udp is statistically uncommon and, absent a documented legacy TACACS-database deployment, is worth investigating rather than assuming a normal service — though UDP's connectionless nature means apparent "open|filtered" results are common scan noise and not by themselves evidence of a live listener. The companion 65/tcp registration shares the same tacacs-ds name, the same assignee, and the same blank reference, so the pair is best read as one legacy TACACS-family reservation spanning both transports.

IANA assignment
tacacs-ds — "TACACS-Database Service"; reference (blank — no RFC cited in IANA registry); assignee Kathy Huber; dual-registered 65/tcp + 65/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry line 147; 65/tcp on line 146)
Range class
well-known (0–1023)
Registration / modification date
blank in IANA registry (recorded as null; not fabricated) [Confirmed]
Related ports
65/tcp (same tacacs-ds assignment); TACACS+ on TCP/49 (the modern successor); the AAA cluster (RADIUS 1812/1813)

Primary use

legacy TACACS-Database Service — centralized AAA-database lookups in the TACACS family; no active implementation found

[Likely] — IANA registry; https://www.portnox.com/cybersecurity-101/tacacs-port/

Other/unofficial uses

none verified; the active TACACS ecosystem uses TACACS+ on TCP/49, not port 65 [Likely] — Cisco IOS TACACS+ configuration guide; https://docs.oracle.com/en/industries/communications/session-border-controller/8.2.0/acliconfiguration/tacacs-aaa.html

Common software

Unknown — no current software found that actively uses 65/udp for tacacs-ds [Unknown]

Security implications

no CVEs and no malware/trojan associations identified; not on common scanning watchlists or Shodan top-port lists; expected internet exposure negligible given no known active use

[Likely] — https://www.auditmypc.com/udp-port-65.asp

Typically seen on

not observed in published exposure data; a responsive 65/udp is an anomaly worth investigating

Analyst note
A legacy TACACS-family registration with no live implementation found. Treat an open 65/udp as uncommon and worth investigating; remember UDP "open|filtered" results are frequently scan artifacts, not confirmed listeners.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
tacacs-ds UDP TACACS-Database Service 0.07%
tacacs-ds TCP TACACS-Database Service 0.00%
IANA name
tacacs-ds
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.