Network port detail · UDP/TCP

89

Su-mit-tg
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
Original protocol predates encryption and is completely defunct. No CVE is associated with the su-mit-tg service. Some port-reference databases (e.g., auditmypc.com) attach generic trojan/virus warnings to port 89, but no specific named malware family with a documented tie to this port was found in sourced records — treat as boilerplate, not evidence. Port is in the well-known range (0-1023), so binding requires root on Unix-like systems. Any traffic on TCP 89 today is not the SU/MIT Telnet Gateway; it is most plausibly automated scanning, misconfiguration, or opportunistic probing. An active listener is anomalous and warrants investigation.
// analyst note
Any open TCP 89 is statistically rare and not the historical gateway; treat as a misconfiguration, scan artifact, or possible backdoor and investigate rather than assume legitimate use.
[ 01 ] — Context

About port 89/tcp.

Updated  ·  Confidence: High

Port 89/tcp is registered with IANA as su-mit-tg with the description "SU/MIT Telnet Gateway," contact [Mark_Crispin], and a blank reference field (dual-registered identically on TCP and UDP). The "SU/MIT" pair refers to Stanford University and MIT, and the assignment dates to the early-1980s assigned-numbers era — the name appears in the historical IANA port lists carried forward from documents such as RFC 943. The service was a Telnet gateway that bridged terminal sessions between institutional hosts at a time when networking stacks and terminal conventions were not yet uniform across sites; a user would reach the gateway on port 89, which mediated the cross-site Telnet connection. Mark Crispin, the assignee, was a Stanford systems programmer best known later as the author of the IMAP protocol, which places this registration firmly in the pre-TCP/IP-convergence environment of WAITS-era PDP-10 systems. No RFC is cited in the IANA registry as the authoritative protocol reference — the entry lists only the contact — so the IANA reference field is honestly blank. For an analyst, port 89 matters almost entirely as a curiosity: the original service is defunct, no mainstream operating system or current software listens on 89 by default, and the gateway implementations ran on hardware and operating systems retired decades ago. Because the port sits in the well-known/system range (0–1023), binding a listener requires root on Unix-like systems. Any traffic observed on TCP 89 today is therefore not the SU/MIT Telnet Gateway; it is most plausibly automated port scanning across all well-known ports, a misconfiguration, or opportunistic probing. No CVE is associated with the original su-mit-tg service, and while some port-reference databases attach generic trojan/virus warnings to port 89, no specific named malware family with a documented tie to this port was found in sourced records — treat such flags as boilerplate rather than evidence. An active listener on TCP 89 is unusual enough to warrant investigation; a connection attempt in firewall logs is common and not inherently alarming.

IANA assignment
su-mit-tg — "SU/MIT Telnet Gateway"; contact [Mark_Crispin]; reference blank (no RFC cited in IANA registry); dual-registered 89/tcp + 89/udp with identical name and description [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry)
Range class
well-known / system (0–1023) — binding requires root on Unix-like systems [Confirmed] — IANA registry port-range definition
Registration / modification date
blank in the IANA registry [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (date columns empty)
Status
defunct / legacy — IANA assignment retained but the service has been inactive since the 1980s [Confirmed] — IANA registry, connected.app

Primary use

legacy Telnet gateway bridging cross-institutional terminal sessions between Stanford University (SU) and MIT in the early-1980s pre-TCP/IP-convergence era; assignee Mark Crispin (later the author of IMAP). The service is defunct

[Likely] — IANA registry, RFC 943 assigned-numbers lineage, Wikipedia (Mark Crispin)

Common software

no known current open-source or commercial software listens on TCP 89 by default; original implementation was specific to retired Stanford/MIT systems

[Likely] — connected.app port-89 reference, AirVPN forum

Security implications

original protocol predates encryption; no CVE associated with su-mit-tg; some port databases attach generic trojan/virus warnings to port 89 but no specific named malware family was confirmed in sourced records; an active listener today is anomalous and worth investigating

[Likely] — connected.app, auditmypc.com (generic flag)

Exposure / scan notes

no specific Shodan/Censys host-count data found in sourced results as of June 2026; port is routinely swept by mass scanners as part of full well-known-port coverage; expected real-world exposure is very low given the absence of any active service

[Likely] — Shodan ports listing
Analyst note
Any open TCP 89 is statistically rare and not the historical gateway; treat as a misconfiguration, scan artifact, or possible backdoor and investigate rather than assume legitimate use.
[ 02 ] — Context

About port 89/udp.

Updated  ·  Confidence: High

Port 89/udp is registered with IANA as su-mit-tg with the description "SU/MIT Telnet Gateway," assignee and contact [Mark_Crispin], and blank Registration Date, Modification Date, and Reference fields — the same assignment is mirrored on 89/tcp, making this a dual TCP/UDP registration. The "SU/MIT Telnet Gateway" name reflects its origin as a late-1970s-to-early-1980s bridge between Stanford University (SU), which ran WAITS on PDP-10 hardware, and MIT, whose machines used an incompatible networking stack; a user connected to the gateway host on port 89 and the gateway performed the protocol translation needed to reach the far side. The listed assignee, Mark Crispin (1956–2012), was the Stanford systems programmer better known for authoring IMAP (port 143) and SUPDUP (port 95). No RFC is cited for the su-mit-tg assignment, and the IANA reference field stays blank. The protocol was rendered obsolete once TCP/IP converged as the universal internet standard, and no known implementations have survived; for an analyst this means traffic on 89/udp today is essentially never the legitimate protocol. A frequent misread is to conflate this port with OSPF: OSPF uses IP protocol number 89 (encapsulated directly in IP, not in UDP or TCP), so OSPF traffic does not appear as UDP port 89 — the shared number 89 is coincidental. Any observed 89/udp activity is more plausibly a general port-scan sweep or a historical malware probe than a working SU/MIT Telnet Gateway, and blocking the port at the perimeter carries no operational cost for modern networks.

IANA assignment
su-mit-tg — "SU/MIT Telnet Gateway"; reference (blank — no RFC cited in IANA registry); assignee/contact [Mark_Crispin]; dual-registered 89/tcp + 89/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry lines 246–247)
Range class
well-known (0–1023) [Confirmed] — port 89 < 1024
Registration/modification date
blank in the IANA registry — none recorded [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry line 247
Status
obsolete / undeployed — assigned but no active implementations; superseded by universal TCP/IP adoption [Likely] — connected.app/he/ports/89
Related ports
89/tcp (identical dual registration); Crispin's other assignments — 143 (IMAP), 95 (SUPDUP)

Primary use

legacy Telnet gateway bridging Stanford (WAITS/PDP-10) and MIT's incompatible networking stack; performs protocol translation for cross-institution Telnet sessions

[Likely] — connected.app/he/ports/89, speedguide.net/port.php?port=89

Security implications

today's traffic is not the legitimate protocol; activity likely reflects scanner sweeps or historical malware probes (auditmypc.com notes past trojan/virus use but names no active family); OSPF protocol-89 vs UDP-port-89 confusion is a common misread (OSPF is IP protocol 89, not a UDP port); no meaningful internet-wide exposure footprint in current scan data

[Likely/Threat-reported] — auditmypc.com/udp-port-89.asp, learningnetwork.cisco.com (OSPF IP protocol 89)
Assignee background
Mark Crispin (1956–2012), Stanford systems programmer, also author of IMAP (port 143) and SUPDUP (port 95) [Likely] — connected.app/he/ports/89
Analyst note
An open or active 89/udp is statistically rare and historically meaningless as a live service — treat as a scan artifact, decoy, or misattributed OSPF/number confusion rather than a working SU/MIT Telnet Gateway.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
su-mit-tg UDP SU/MIT Telnet Gateway 0.05%
su-mit-tg TCP SU/MIT Telnet Gateway 0.04%
IANA name
su-mit-tg
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.