72
Summary
- // if you see it open
- No published CVEs and no documented malware associations for port 72. Not flagged as a trojan/virus port by the auditmypc community database. SANS Internet Storm Center records only low background inbound scanning consistent with broad low-port sweeps, not targeted exploitation. The protocol is obsolete and unimplemented in modern software, so any responsive listener on 72/tcp is anomalous and should be investigated; general guidance is to block at the perimeter unless a specific documented need exists.
- // analyst note
- NETRJS is obsolete and unimplemented in modern software; treat an open port 72 as anomalous rather than a normal service.
About port 72/tcp.
Port 72/tcp is registered with IANA as netrjs-2 with the description "Remote Job Service" and a blank reference field, and it is dual-registered on TCP and UDP. It is the second of four contiguous NETRJS entries spanning ports 71–74 (netrjs-1 through netrjs-4), all carrying the same "Remote Job Service" description. NETRJS — the Network Remote Job Entry/Service protocol — was developed at UCLA's Campus Computing Network (CCN) to let ARPANET users submit batch jobs to remote IBM mainframes through a virtual card reader and retrieve output over virtual printer and punch channels; the 71–74 port block let the distinct logical subchannels (operator console, reader, printer, punch) be multiplexed across separate TCP connections. The authoritative specification is RFC 740 (NETRJS Protocol, R. T. Braden, November 22, 1977), with earlier groundwork in RFC 88 and RFC 325. Critically, the IANA port-registry entry for 72/tcp itself cites no RFC in its Reference column — that column is genuinely blank, even though RFC 740 is the historical spec, so the structured field stays empty. For an analyst the protocol is effectively dead: no modern software implements NETRJS, and nmap-services records an open-frequency of roughly 0.000013, meaning port 72 is almost never found open in real-world scans. There are no published CVEs and no documented malware associations for this port; the auditmypc community database does not flag it as a trojan/virus port. The low-level inbound probing the SANS Internet Storm Center records against port 72 is consistent with broad automated sweeps of low-numbered ports rather than any targeted exploitation of NETRJS. Any responsive listener on 72/tcp on a modern host would therefore be anomalous and worth investigating; general hardening guidance is to block it at the perimeter absent a specific documented need.
- IANA assignment
netrjs-2— "Remote Job Service"; reference (blank — no RFC cited in IANA registry); assignee/contact blank; dual-registered 72/tcp + 72/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry lines 168–169)- Range class
- well-known (0–1023)
- Prevalence
- nmap-services open-frequency ≈ 0.000013 (virtually never open) [Confirmed] — nmap-services file
- Related ports
- the NETRJS cluster 71/73/74 (
netrjs-1,netrjs-3,netrjs-4)
Primary use
NETRJS (Network Remote Job Entry/Service) — ARPANET-era batch-job submission to remote IBM mainframes via virtual card reader / printer / punch channels; one of four port variants (71–74). RFC 740 (Braden, Nov 22, 1977) is the spec
Other/unofficial uses
none known; legacy ARPANET design with no modern equivalent [Confirmed]
Security implications
no published CVEs, no known malware associations; not flagged as a trojan/virus port by auditmypc; SANS ISC shows only low background scan noise. A responsive listener today is anomalous and should be investigated; block at perimeter unless specifically needed
Typically seen on
historically CCN/IBM mainframe RJS servers on the ARPANET; otherwise an anomaly on a modern host
- Analyst note
- NETRJS is obsolete and unimplemented in modern software; treat an open port 72 as anomalous rather than a normal service.
About port 72/udp.
Port 72/udp is registered with IANA as netrjs-2 with the description "Remote Job Service," and is dual-registered on TCP and UDP — both 72/tcp and 72/udp carry the same netrjs-2 / Remote Job Service assignment. The Assignee, Contact, Registration Date, Modification Date, and Reference columns are all blank in the current IANA registry for this row; those are recorded blanks, not unknowns, and no RFC is cited against port 72 specifically. The name belongs to a block of four contiguous assignments — ports 71–74, labelled netrjs-1 through netrjs-4 — all sharing the "Remote Job Service" description and historically attributed to Bob Braden. The underlying protocol, NETRJS (Network Remote Job Service), was a 1970s ARPANET design from the UCLA Campus Computing Network for submitting and retrieving batch jobs on IBM mainframes: a user connected to a contact socket, submitted JCL, monitored job status, and retrieved printed or punched output remotely. The definitive specification is RFC 740 (November 1977), which distinguishes the protocol's entry points by character encoding (EBCDIC / ASCII), not by these sequential port numbers — the netrjs-1/2/3/4 numbering across ports 71–74 appears in later assigned-numbers registries (RFC 990, RFC 1700) and is best understood as an IANA bookkeeping artefact, a reserved slot in the netrjs block rather than a separately specified sub-protocol. For an analyst, port 72 is of historical interest only: the protocol is entirely obsolete, no current software uses it, and it carries no notable internet-exposure profile, no CVEs, and no exploit-framework presence. Unexpected inbound traffic on 72/udp in a modern network most likely reflects a port-scan sweep or a misconfigured scanner rather than a legitimate service.
- IANA assignment
netrjs-2— "Remote Job Service"; reference (blank — no RFC cited in IANA registry); assignee (blank); contact (blank); dual-registered 72/tcp + 72/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 169; IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- IANA reference
- blank on port 72 specifically; RFC 740 is the authoritative technical reference and is cited for the netrjs block in historical assigned-numbers RFCs (RFC 990, RFC 1700) [Confirmed] — RFC 1700, IANA registry
- Status
- legacy / obsolete; IANA registration retained as historical record [Confirmed] — RFC 88, RFC 740
- Related ports
- 71/udp (netrjs-1), 73/udp (netrjs-3), 74/udp (netrjs-4) — the netrjs block
Primary use
NETRJS (Network Remote Job Service) — 1970s ARPANET protocol for remote batch-job submission and retrieval on IBM mainframes; entirely obsolete
Protocol detail
netrjs-1/2/3/4 across ports 71–74 is an IANA registry artefact; NETRJS specs (RFC 88, RFC 189, RFC 740) distinguish entry-points by character encoding (EBCDIC/ASCII), not by sequential port number
Common software
none current; historically UCLA Campus Computing Network's RJS subsystem on IBM mainframes (OS/360-era). No modern implementations in active use
Security implications
negligible attack surface; not among commonly scanned/attacked ports; no CVEs or exploit frameworks found; unusual inbound traffic likely indicates a scan sweep or misconfigured scanner
- Analyst note
- Port 72/udp is a historical ARPANET-era registration with no live use; treat any traffic as anomalous (scan/decoy) rather than a legitimate service.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| netrjs-2 | UDP | Remote Job Service | 0.05% |
| netrjs-2 | TCP | Remote Job Service | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.