89
Summary
- // if you see it open
- Original protocol predates encryption and is completely defunct. No CVE is associated with the su-mit-tg service. Some port-reference databases (e.g., auditmypc.com) attach generic trojan/virus warnings to port 89, but no specific named malware family with a documented tie to this port was found in sourced records — treat as boilerplate, not evidence. Port is in the well-known range (0-1023), so binding requires root on Unix-like systems. Any traffic on TCP 89 today is not the SU/MIT Telnet Gateway; it is most plausibly automated scanning, misconfiguration, or opportunistic probing. An active listener is anomalous and warrants investigation.
- // analyst note
- Any open TCP 89 is statistically rare and not the historical gateway; treat as a misconfiguration, scan artifact, or possible backdoor and investigate rather than assume legitimate use.
About port 89/tcp.
Port 89/tcp is registered with IANA as su-mit-tg with the description "SU/MIT Telnet Gateway," contact [Mark_Crispin], and a blank reference field (dual-registered identically on TCP and UDP). The "SU/MIT" pair refers to Stanford University and MIT, and the assignment dates to the early-1980s assigned-numbers era — the name appears in the historical IANA port lists carried forward from documents such as RFC 943. The service was a Telnet gateway that bridged terminal sessions between institutional hosts at a time when networking stacks and terminal conventions were not yet uniform across sites; a user would reach the gateway on port 89, which mediated the cross-site Telnet connection. Mark Crispin, the assignee, was a Stanford systems programmer best known later as the author of the IMAP protocol, which places this registration firmly in the pre-TCP/IP-convergence environment of WAITS-era PDP-10 systems. No RFC is cited in the IANA registry as the authoritative protocol reference — the entry lists only the contact — so the IANA reference field is honestly blank. For an analyst, port 89 matters almost entirely as a curiosity: the original service is defunct, no mainstream operating system or current software listens on 89 by default, and the gateway implementations ran on hardware and operating systems retired decades ago. Because the port sits in the well-known/system range (0–1023), binding a listener requires root on Unix-like systems. Any traffic observed on TCP 89 today is therefore not the SU/MIT Telnet Gateway; it is most plausibly automated port scanning across all well-known ports, a misconfiguration, or opportunistic probing. No CVE is associated with the original su-mit-tg service, and while some port-reference databases attach generic trojan/virus warnings to port 89, no specific named malware family with a documented tie to this port was found in sourced records — treat such flags as boilerplate rather than evidence. An active listener on TCP 89 is unusual enough to warrant investigation; a connection attempt in firewall logs is common and not inherently alarming.
- IANA assignment
su-mit-tg— "SU/MIT Telnet Gateway"; contact[Mark_Crispin]; reference blank (no RFC cited in IANA registry); dual-registered 89/tcp + 89/udp with identical name and description [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry)- Range class
- well-known / system (0–1023) — binding requires root on Unix-like systems [Confirmed] — IANA registry port-range definition
- Registration / modification date
- blank in the IANA registry [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (date columns empty)
- Status
- defunct / legacy — IANA assignment retained but the service has been inactive since the 1980s [Confirmed] — IANA registry, connected.app
Primary use
legacy Telnet gateway bridging cross-institutional terminal sessions between Stanford University (SU) and MIT in the early-1980s pre-TCP/IP-convergence era; assignee Mark Crispin (later the author of IMAP). The service is defunct
Common software
no known current open-source or commercial software listens on TCP 89 by default; original implementation was specific to retired Stanford/MIT systems
Security implications
original protocol predates encryption; no CVE associated with su-mit-tg; some port databases attach generic trojan/virus warnings to port 89 but no specific named malware family was confirmed in sourced records; an active listener today is anomalous and worth investigating
Exposure / scan notes
no specific Shodan/Censys host-count data found in sourced results as of June 2026; port is routinely swept by mass scanners as part of full well-known-port coverage; expected real-world exposure is very low given the absence of any active service
- Analyst note
- Any open TCP 89 is statistically rare and not the historical gateway; treat as a misconfiguration, scan artifact, or possible backdoor and investigate rather than assume legitimate use.
About port 89/udp.
Port 89/udp is registered with IANA as su-mit-tg with the description "SU/MIT Telnet Gateway," assignee and contact [Mark_Crispin], and blank Registration Date, Modification Date, and Reference fields — the same assignment is mirrored on 89/tcp, making this a dual TCP/UDP registration. The "SU/MIT Telnet Gateway" name reflects its origin as a late-1970s-to-early-1980s bridge between Stanford University (SU), which ran WAITS on PDP-10 hardware, and MIT, whose machines used an incompatible networking stack; a user connected to the gateway host on port 89 and the gateway performed the protocol translation needed to reach the far side. The listed assignee, Mark Crispin (1956–2012), was the Stanford systems programmer better known for authoring IMAP (port 143) and SUPDUP (port 95). No RFC is cited for the su-mit-tg assignment, and the IANA reference field stays blank. The protocol was rendered obsolete once TCP/IP converged as the universal internet standard, and no known implementations have survived; for an analyst this means traffic on 89/udp today is essentially never the legitimate protocol. A frequent misread is to conflate this port with OSPF: OSPF uses IP protocol number 89 (encapsulated directly in IP, not in UDP or TCP), so OSPF traffic does not appear as UDP port 89 — the shared number 89 is coincidental. Any observed 89/udp activity is more plausibly a general port-scan sweep or a historical malware probe than a working SU/MIT Telnet Gateway, and blocking the port at the perimeter carries no operational cost for modern networks.
- IANA assignment
su-mit-tg— "SU/MIT Telnet Gateway"; reference (blank — no RFC cited in IANA registry); assignee/contact[Mark_Crispin]; dual-registered 89/tcp + 89/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry lines 246–247)- Range class
- well-known (0–1023) [Confirmed] — port 89 < 1024
- Registration/modification date
- blank in the IANA registry — none recorded [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 247
- Status
- obsolete / undeployed — assigned but no active implementations; superseded by universal TCP/IP adoption [Likely] — connected.app/he/ports/89
- Related ports
- 89/tcp (identical dual registration); Crispin's other assignments — 143 (IMAP), 95 (SUPDUP)
Primary use
legacy Telnet gateway bridging Stanford (WAITS/PDP-10) and MIT's incompatible networking stack; performs protocol translation for cross-institution Telnet sessions
Security implications
today's traffic is not the legitimate protocol; activity likely reflects scanner sweeps or historical malware probes (auditmypc.com notes past trojan/virus use but names no active family); OSPF protocol-89 vs UDP-port-89 confusion is a common misread (OSPF is IP protocol 89, not a UDP port); no meaningful internet-wide exposure footprint in current scan data
- Assignee background
- Mark Crispin (1956–2012), Stanford systems programmer, also author of IMAP (port 143) and SUPDUP (port 95) [Likely] — connected.app/he/ports/89
- Analyst note
- An open or active 89/udp is statistically rare and historically meaningless as a live service — treat as a scan artifact, decoy, or misattributed OSPF/number confusion rather than a working SU/MIT Telnet Gateway.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| su-mit-tg | UDP | SU/MIT Telnet Gateway | 0.05% |
| su-mit-tg | TCP | SU/MIT Telnet Gateway | 0.04% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.