Network port detail · UDP/TCP

902

Ideafarm-door
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
An exposed 902 flags an ESX/ESXi host or VMware Server — a high-value virtualization target. vmware-authd has had historical vulnerabilities. The ESXi-targeting ransomware ecosystem (e.g. ESXiArgs) primarily hits 427 (SLP) and 443 rather than 902, but 902 should still be restricted to management networks.
// analyst note
An open 902 is a VMware ESXi/Server host; high-value target, keep off public networks.
[ 01 ] — Context

About port 902.

Updated  ·  Confidence: High

Port 902/tcp is registered with IANA as ideafarm-door — not "vmware" — with the TCP description "self documenting Telnet Door" (the UDP row differs verbatim: "self documenting Door: send 0x00 for info"), a blank assignee and contact, and a blank reference field; ideafarm is an obscure, largely deprecated proprietary protocol, and the adjacent port 903 is ideafarm-panic ("self documenting Telnet Panic Door," assigned to Wo o Ideafarm). The dominant real-world use of 902, however, is entirely de-facto: VMware's vmware-authd / host agent. On ESX/ESXi and VMware Server, 902/tcp (and 902/udp) carry host management, virtual-machine remote-console authentication and traffic, and ESX/ESXi heartbeat over UDP; the legacy configuration used port = 902 in the vmware-authd/xinetd config, and remote consoles connect to virtual machines over 902 by default. Broadcom/VMware knowledge-base articles list 902 for vCenter and VI Client host management and heartbeat (with 443 as the web/management port), and although port 903 was historically documented for the remote console, VMware later acknowledged that ESXi does not actually use 903 — console traffic uses 902. The IANA reference field is blank. Security-wise an exposed 902 flags an ESX/ESXi host or VMware Server, a high-value virtualization target; vmware-authd has had historical vulnerabilities, and while the broader ESXi-targeting ransomware ecosystem (such as ESXiArgs) primarily hits 427 (SLP) and 443 rather than 902, the port should still be restricted to management networks. For an analyst, an open 902 is a VMware ESXi or Server host and should be kept off public networks.

IANA assignment
ideafarm-door (NOT "vmware") — TCP "self documenting Telnet Door" / UDP "self documenting Door: send 0x00 for info"; reference (blank — no RFC cited in IANA registry); assignee/contact blank; dual-registered 902/tcp + 902/udp
[IANA-assigned] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023; 902 < 1024)
Prevalence
appears due to VMware deployments; nmap-services de-facto moderate [Well-established] — nmap-services file
Related ports
443 (vSphere/ESXi web & API), 427 (SLP/ESXi), 903 (VMware console, de-facto)

Primary use (de-facto)

VMware vmware-authd / host agent — ESX/ESXi host management and VM remote-console authentication

[Community/de-facto] — VMware/Broadcom KB

Other/unofficial uses

the registered ideafarm-door protocol (obscure, deprecated) [IANA-assigned]

Security implications

an exposed 902 flags a high-value ESX/ESXi host; vmware-authd historical vulnerabilities; ESXi-ransomware ecosystem (primary vector usually 443/427, not 902); restrict to management networks [Well-established/Threat-reported]

Typically seen on

VMware ESX/ESXi hosts, VMware Server

Analyst note
An open 902 is a VMware ESXi/Server host; high-value target, keep off public networks.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
ideafarm-door UDP self documenting Door: send 0x00 for info 0.20%
iss-realsecure TCP ideafarm-door 0.15%
IANA name
ideafarm-door
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.