Network port detail · UDP/TCP

78

Vettcp
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Low observed risk. No known active service to exploit, no documented CVEs, and no significant recorded scanning or threat-actor use. Sits in the well-known range (0-1023), so binding requires elevated privileges on Unix-like systems, limiting casual misuse. Firewalls that filter it typically do so as default policy.
// analyst note
78/tcp is effectively a historic placeholder with no surviving implementation; an open port 78 is statistically rare and should be investigated rather than assumed to be a standard service.
[ 01 ] — Context

About port 78/tcp.

Updated  ·  Confidence: Medium

Port 78/tcp is registered with IANA as vettcp with the description "vettcp," assignee and contact Christopher Leong, and blank registration-date, modification-date, and reference fields; it is dual-registered on TCP and UDP (78/tcp + 78/udp share identical registry entries). The assignment predates the modern registry: vettcp 78/tcp already appears in RFC 1340 (Assigned Numbers, July 1992), so it is one of the long-standing well-known-range entries rather than a recent allocation. Beyond the name and the registration, essentially no primary documentation of vettcp survives — there is no RFC defining a vettcp protocol, no surviving reference implementation, and no software package, operating-system service, or open-source project documented as actively using the port today. The name pattern (a "tcp"-suffixed utility) is consistent with the early-1990s family of throughput- and connectivity-validation tools, but any claim that vettcp is specifically a "TCP testing tool" is an inference from naming and era, not a fact sourced from vettcp documentation, which does not appear to exist publicly. For an analyst the practical reality is that 78/tcp is effectively a historic placeholder: it has no known active services to exploit, no documented CVEs, and no significant recorded scanning or threat-actor activity in publicly indexed sources. One consumer-facing port-lookup site (AuditMyPC) notes that a trojan or virus "has used this port in the past" but supplies no malware name, date, or citation, so that claim cannot be verified and should be treated as low-confidence boilerplate rather than a real association. Because the port sits in the well-known range (0–1023) it requires elevated privileges to bind on Unix-like systems, which limits casual misuse; firewall teams that leave it filtered are typically applying default policy rather than responding to an active threat. A responsive 78/tcp is therefore statistically unusual and worth a look as an anomaly, a decoy, or a custom service rather than as a recognizable standard protocol.

IANA assignment
vettcp — description "vettcp"; reference (blank — no RFC cited in IANA registry); assignee/contact Christopher Leong; dual-registered 78/tcp + 78/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023)
Registration / modification dates
blank in the IANA registry — stays Unknown (no fabrication) [Confirmed] — IANA registry
Related ports
contemporaneous well-known-range registrations near it (e.g. finger 79, ports in the small-services era)

Primary use

legacy vettcp registration; no surviving protocol documentation or reference implementation. Name/era are consistent with an early-1990s TCP connectivity/throughput utility, but the specific function is undocumented

[Likely] — IANA registry; RFC 1340

Common software / active use

Unknown — no software, OS service, or open-source project documented as using 78/tcp today; appears to be a historic placeholder [Unknown]

Security implications

low observed risk — no known active service, no documented CVEs, no significant recorded scanning. Well-known range (0–1023) requires elevated privileges to bind on Unix-like systems [Likely]

Malware associations

none verifiable — one consumer port-lookup site (AuditMyPC) makes an unsourced "trojan/virus has used this port" claim with no malware name or date; treat as low-confidence boilerplate, not a real association

[Likely] — AuditMyPC tcp-port-78

Typically seen on

no characteristic host profile; a responsive 78/tcp is an anomaly worth investigating as a decoy or custom service

Historical reference
present in RFC 1340 (Assigned Numbers, July 1992) as vettcp 78/tcp — no dedicated RFC defines the protocol [Confirmed] — RFC 1340
Analyst note
78/tcp is effectively a historic placeholder with no surviving implementation; an open port 78 is statistically rare and should be investigated rather than assumed to be a standard service.
[ 02 ] — Context

About port 78/udp.

Updated  ·  Confidence: Medium

Port 78/udp is registered with IANA under the service name vettcp, with the assignee and contact both listed as Christopher Leong. The registry carries no expanded description (the description column simply repeats the service name), no RFC or document reference, and no registration or modification date — those columns are blank in the IANA Service Name and Transport Protocol Port Number Registry, and they are recorded here as null rather than guessed. Port 78 is dual-registered on both TCP and UDP with the same service name, assignee, and contact. Beyond the bare assignment, no public RFC, specification, or vendor documentation describing what vettcp actually does has been located; the name suggests some kind of TCP vetting or testing utility, but that is inference from the string alone and is not confirmed by any source. In practice no known software ships on this port and there are no documented active deployments, so its presence in any port table is essentially a legacy registry reservation. No CVEs, exploits, or significant internet-wide scanning data are specifically attributed to 78/udp; AuditMyPC flags the port as historically trojan-associated but names no specific malware family, which reads as a generic placeholder warning rather than an attributed threat. For an analyst, traffic on 78/udp has no legitimate service to explain it and is best treated as anomalous and worth investigating.

IANA assignment
vettcp — service name (the description column repeats the service name; no expanded text); reference blank (no RFC cited in IANA registry); assignee and contact both Christopher Leong; dual-registered 78/tcp + 78/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry lines 180–181)
Range class
well-known (0–1023) [Confirmed]
Registration date / modification date
blank in registry — null, not fabricated [Confirmed] — IANA registry (line 181)
Related ports
78/tcp (same vettcp assignment, same assignee/contact)

Primary use

Unknown — no public specification or documentation found; name implies a TCP vetting/testing tool but this is inference from the name only [Unknown]

Common software

none identified shipping on 78/udp in any source found

[Likely] — https://www.auditmypc.com/udp-port-78.asp

Security implications

no CVEs, exploits, or notable Shodan/internet-wide scanning attributed specifically to 78/udp; AuditMyPC flags it as historically trojan-associated but names no specific malware (generic placeholder warning); with no legitimate active service, any 78/udp traffic should be treated as anomalous

[Likely] — https://www.auditmypc.com/udp-port-78.asp

Typically seen on

no documented active deployments — an open 78/udp is an anomaly worth investigating

Analyst note
legitimate use is undocumented; treat a responsive 78/udp as anomalous rather than a normal service.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
vettcp UDP 0.06%
vettcp TCP 0.00%
IANA name
vettcp
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.