Network port detail · UDP/TCP

72

Netrjs-2
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No published CVEs and no documented malware associations for port 72. Not flagged as a trojan/virus port by the auditmypc community database. SANS Internet Storm Center records only low background inbound scanning consistent with broad low-port sweeps, not targeted exploitation. The protocol is obsolete and unimplemented in modern software, so any responsive listener on 72/tcp is anomalous and should be investigated; general guidance is to block at the perimeter unless a specific documented need exists.
// analyst note
NETRJS is obsolete and unimplemented in modern software; treat an open port 72 as anomalous rather than a normal service.
[ 01 ] — Context

About port 72/tcp.

Updated  ·  Confidence: High

Port 72/tcp is registered with IANA as netrjs-2 with the description "Remote Job Service" and a blank reference field, and it is dual-registered on TCP and UDP. It is the second of four contiguous NETRJS entries spanning ports 71–74 (netrjs-1 through netrjs-4), all carrying the same "Remote Job Service" description. NETRJS — the Network Remote Job Entry/Service protocol — was developed at UCLA's Campus Computing Network (CCN) to let ARPANET users submit batch jobs to remote IBM mainframes through a virtual card reader and retrieve output over virtual printer and punch channels; the 71–74 port block let the distinct logical subchannels (operator console, reader, printer, punch) be multiplexed across separate TCP connections. The authoritative specification is RFC 740 (NETRJS Protocol, R. T. Braden, November 22, 1977), with earlier groundwork in RFC 88 and RFC 325. Critically, the IANA port-registry entry for 72/tcp itself cites no RFC in its Reference column — that column is genuinely blank, even though RFC 740 is the historical spec, so the structured field stays empty. For an analyst the protocol is effectively dead: no modern software implements NETRJS, and nmap-services records an open-frequency of roughly 0.000013, meaning port 72 is almost never found open in real-world scans. There are no published CVEs and no documented malware associations for this port; the auditmypc community database does not flag it as a trojan/virus port. The low-level inbound probing the SANS Internet Storm Center records against port 72 is consistent with broad automated sweeps of low-numbered ports rather than any targeted exploitation of NETRJS. Any responsive listener on 72/tcp on a modern host would therefore be anomalous and worth investigating; general hardening guidance is to block it at the perimeter absent a specific documented need.

IANA assignment
netrjs-2 — "Remote Job Service"; reference (blank — no RFC cited in IANA registry); assignee/contact blank; dual-registered 72/tcp + 72/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry lines 168–169)
Range class
well-known (0–1023)
Prevalence
nmap-services open-frequency ≈ 0.000013 (virtually never open) [Confirmed] — nmap-services file
Related ports
the NETRJS cluster 71/73/74 (netrjs-1, netrjs-3, netrjs-4)

Primary use

NETRJS (Network Remote Job Entry/Service) — ARPANET-era batch-job submission to remote IBM mainframes via virtual card reader / printer / punch channels; one of four port variants (71–74). RFC 740 (Braden, Nov 22, 1977) is the spec

[Confirmed] — RFC 740; IANA registry

Other/unofficial uses

none known; legacy ARPANET design with no modern equivalent [Confirmed]

Security implications

no published CVEs, no known malware associations; not flagged as a trojan/virus port by auditmypc; SANS ISC shows only low background scan noise. A responsive listener today is anomalous and should be investigated; block at perimeter unless specifically needed

[Confirmed/Threat-reported] — SANS ISC, auditmypc, nmap-services

Typically seen on

historically CCN/IBM mainframe RJS servers on the ARPANET; otherwise an anomaly on a modern host

Analyst note
NETRJS is obsolete and unimplemented in modern software; treat an open port 72 as anomalous rather than a normal service.
[ 02 ] — Context

About port 72/udp.

Updated  ·  Confidence: High

Port 72/udp is registered with IANA as netrjs-2 with the description "Remote Job Service," and is dual-registered on TCP and UDP — both 72/tcp and 72/udp carry the same netrjs-2 / Remote Job Service assignment. The Assignee, Contact, Registration Date, Modification Date, and Reference columns are all blank in the current IANA registry for this row; those are recorded blanks, not unknowns, and no RFC is cited against port 72 specifically. The name belongs to a block of four contiguous assignments — ports 71–74, labelled netrjs-1 through netrjs-4 — all sharing the "Remote Job Service" description and historically attributed to Bob Braden. The underlying protocol, NETRJS (Network Remote Job Service), was a 1970s ARPANET design from the UCLA Campus Computing Network for submitting and retrieving batch jobs on IBM mainframes: a user connected to a contact socket, submitted JCL, monitored job status, and retrieved printed or punched output remotely. The definitive specification is RFC 740 (November 1977), which distinguishes the protocol's entry points by character encoding (EBCDIC / ASCII), not by these sequential port numbers — the netrjs-1/2/3/4 numbering across ports 71–74 appears in later assigned-numbers registries (RFC 990, RFC 1700) and is best understood as an IANA bookkeeping artefact, a reserved slot in the netrjs block rather than a separately specified sub-protocol. For an analyst, port 72 is of historical interest only: the protocol is entirely obsolete, no current software uses it, and it carries no notable internet-exposure profile, no CVEs, and no exploit-framework presence. Unexpected inbound traffic on 72/udp in a modern network most likely reflects a port-scan sweep or a misconfigured scanner rather than a legitimate service.

IANA assignment
netrjs-2 — "Remote Job Service"; reference (blank — no RFC cited in IANA registry); assignee (blank); contact (blank); dual-registered 72/tcp + 72/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 169; IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
IANA reference
blank on port 72 specifically; RFC 740 is the authoritative technical reference and is cited for the netrjs block in historical assigned-numbers RFCs (RFC 990, RFC 1700) [Confirmed] — RFC 1700, IANA registry
Status
legacy / obsolete; IANA registration retained as historical record [Confirmed] — RFC 88, RFC 740
Related ports
71/udp (netrjs-1), 73/udp (netrjs-3), 74/udp (netrjs-4) — the netrjs block

Primary use

NETRJS (Network Remote Job Service) — 1970s ARPANET protocol for remote batch-job submission and retrieval on IBM mainframes; entirely obsolete

[Confirmed] — RFC 740

Protocol detail

netrjs-1/2/3/4 across ports 71–74 is an IANA registry artefact; NETRJS specs (RFC 88, RFC 189, RFC 740) distinguish entry-points by character encoding (EBCDIC/ASCII), not by sequential port number

[Confirmed] — RFC 740, RFC 503

Common software

none current; historically UCLA Campus Computing Network's RJS subsystem on IBM mainframes (OS/360-era). No modern implementations in active use

[Confirmed] — RFC 740

Security implications

negligible attack surface; not among commonly scanned/attacked ports; no CVEs or exploit frameworks found; unusual inbound traffic likely indicates a scan sweep or misconfigured scanner

[Likely] — ISC SANS
Analyst note
Port 72/udp is a historical ARPANET-era registration with no live use; treat any traffic as anomalous (scan/decoy) rather than a legitimate service.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
netrjs-2 UDP Remote Job Service 0.05%
netrjs-2 TCP Remote Job Service 0.00%
IANA name
netrjs-2
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.