902
Summary
- // if you see it open
- An exposed 902 flags an ESX/ESXi host or VMware Server — a high-value virtualization target. vmware-authd has had historical vulnerabilities. The ESXi-targeting ransomware ecosystem (e.g. ESXiArgs) primarily hits 427 (SLP) and 443 rather than 902, but 902 should still be restricted to management networks.
- // analyst note
- An open 902 is a VMware ESXi/Server host; high-value target, keep off public networks.
About port 902.
Port 902/tcp is registered with IANA as ideafarm-door — not "vmware" — with the TCP description "self documenting Telnet Door" (the UDP row differs verbatim: "self documenting Door: send 0x00 for info"), a blank assignee and contact, and a blank reference field; ideafarm is an obscure, largely deprecated proprietary protocol, and the adjacent port 903 is ideafarm-panic ("self documenting Telnet Panic Door," assigned to Wo o Ideafarm). The dominant real-world use of 902, however, is entirely de-facto: VMware's vmware-authd / host agent. On ESX/ESXi and VMware Server, 902/tcp (and 902/udp) carry host management, virtual-machine remote-console authentication and traffic, and ESX/ESXi heartbeat over UDP; the legacy configuration used port = 902 in the vmware-authd/xinetd config, and remote consoles connect to virtual machines over 902 by default. Broadcom/VMware knowledge-base articles list 902 for vCenter and VI Client host management and heartbeat (with 443 as the web/management port), and although port 903 was historically documented for the remote console, VMware later acknowledged that ESXi does not actually use 903 — console traffic uses 902. The IANA reference field is blank. Security-wise an exposed 902 flags an ESX/ESXi host or VMware Server, a high-value virtualization target; vmware-authd has had historical vulnerabilities, and while the broader ESXi-targeting ransomware ecosystem (such as ESXiArgs) primarily hits 427 (SLP) and 443 rather than 902, the port should still be restricted to management networks. For an analyst, an open 902 is a VMware ESXi or Server host and should be kept off public networks.
- IANA assignment
ideafarm-door(NOT "vmware") — TCP "self documenting Telnet Door" / UDP "self documenting Door: send 0x00 for info"; reference (blank — no RFC cited in IANA registry); assignee/contact blank; dual-registered 902/tcp + 902/udp[IANA-assigned] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023; 902 < 1024)
- Prevalence
- appears due to VMware deployments; nmap-services de-facto moderate [Well-established] — nmap-services file
- Related ports
- 443 (vSphere/ESXi web & API), 427 (SLP/ESXi), 903 (VMware console, de-facto)
Primary use (de-facto)
VMware vmware-authd / host agent — ESX/ESXi host management and VM remote-console authentication
Other/unofficial uses
the registered ideafarm-door protocol (obscure, deprecated) [IANA-assigned]
Security implications
an exposed 902 flags a high-value ESX/ESXi host; vmware-authd historical vulnerabilities; ESXi-ransomware ecosystem (primary vector usually 443/427, not 902); restrict to management networks [Well-established/Threat-reported]
Typically seen on
VMware ESX/ESXi hosts, VMware Server
- Analyst note
- An open 902 is a VMware ESXi/Server host; high-value target, keep off public networks.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| ideafarm-door | UDP | self documenting Door: send 0x00 for info | 0.20% |
| iss-realsecure | TCP | ideafarm-door | 0.15% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.