91
Summary
- // if you see it open
- SANS ISC shows background scanning of 91/tcp from distributed sources at a low/green threat level, consistent with opportunistic internet-wide scanning. No CVEs, named malware families, or confirmed backdoors are associated with this port. A third-party site (auditmypc.com) flags a historical trojan association but names no malware and provides no evidence — unverified.
- // analyst note
- A real MIT Dover spooler on port 91 would be extraordinary; an open 91 today is more plausibly a custom service or scan artifact than the registered service. The IANA reference field is blank.
About port 91/tcp.
Port 91/tcp is registered with IANA as mit-dov with the description "MIT Dover Spooler," assignee Eliot Moss, and a blank reference field (dual-registered on TCP and UDP — 91/udp carries the same mit-dov name and description). The name traces to the Xerox Dover, a late-1970s Xerox PARC raster laser printer, and to MIT's print-spooling setup for it: through the early 1980s MIT ran a Dover spooler on its ITS (Incompatible Timesharing System) machines, queuing jobs that were ultimately driven to the printer via a Xerox Alto running the SPRUCE print software, with documents shipped over the Ethernet File Transfer Protocol (EFTP). The IANA service name mit-dov is a direct artifact of that history. For an analyst the practical reality is that this protocol is obsolete: the Dover printer, the Alto, and the ITS spooler are all museum-era technology, and no current commercial or open-source software is known to listen on port 91 for this purpose. The IANA registry cites no RFC for the assignment, so the reference column is genuinely blank rather than missing. SANS ISC data shows background scanning of 91/tcp from distributed sources at a low/green threat level, consistent with opportunistic internet-wide scanning rather than targeted exploitation; no CVEs, named malware families, or confirmed backdoors are tied to this port. One third-party site (auditmypc.com) flags a historical trojan association, but names no malware and offers no supporting evidence, so that claim is unverified. In practice an open port 91 today is far more likely to be an unrelated custom service squatting on the number than a real MIT Dover spooler.
- IANA assignment
mit-dov— "MIT Dover Spooler"; reference (blank — no RFC cited in IANA registry); assignee Eliot Moss; dual-registered 91/tcp + 91/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry- Range class
- well-known (0–1023) [Confirmed]
- Registration date / modification date
- blank in the IANA registry (genuine null, not missing) [Confirmed] — IANA registry
- Related ports
- the legacy/print and small-services neighborhood; contrast modern print protocols (e.g. 515 LPD, 631 IPP)
Primary use
print spooler for the Xerox Dover laser printer; MIT ran a Dover spooler on ITS in the early 1980s, driving the printer via a Xerox Alto (SPRUCE) over EFTP
Common software
MIT ITS Dover spooler and Xerox Alto SPRUCE host — all legacy/historical; no current software known to use this port
Security implications / scanning
SANS ISC shows active background scanning of 91/tcp from distributed sources at green/low threat level; no CVEs, named malware, or confirmed backdoors. An auditmypc.com trojan flag is unsubstantiated (no named malware) — treat as unverified
Typically seen on
historically MIT ITS hosts; today, an anomaly or an unrelated custom service reusing the number
- Analyst note
- A real MIT Dover spooler on port 91 would be extraordinary; an open 91 today is more plausibly a custom service or scan artifact than the registered service. The IANA reference field is blank.
About port 91/udp.
Port 91/udp is registered with IANA under the service name mit-dov, described as "MIT Dover Spooler," with assignee and contact listed as Eliot Moss and a blank reference field. The registration is dual: both 91/tcp and 91/udp carry the same mit-dov service name and description. The protocol is a relic of late-1970s and early-1980s research-network printing. The Dover was a Xerox PARC laser printer (only on the order of thirty-five units were built) deployed at institutions such as the MIT AI Lab and Stanford; the MIT spooler queued print jobs and forwarded them — over CHAOSNET/TCP through a gateway — to a Xerox Alto machine running the SPRUCE spooler, which in turn drove the Dover hardware. Port 91 was registered to carry that spooling traffic over the network. None of this survives in modern software: the Dover and its associated MIT spooler infrastructure are long obsolete, and 91/udp sees no meaningful legitimate traffic on contemporary networks. For an analyst the port's relevance today is almost entirely as an anomaly indicator. SANS ISC shows only low-level opportunistic, internet-wide scanning on port 91 (threat level green as of 2026-06-25), with no documented exploit or CVE targeting it. Some third-party security references note historical malware association with port 91, but no specific, verifiable trojan family is documented in the sources retrieved, so that claim is tagged Likely rather than treated as fact. Because the port carries no legitimate modern service, any inbound traffic on 91/udp to a production host is anomalous and most plausibly reflects misconfiguration, a backdoor, or a decoy rather than a real service — and warrants blocking.
- IANA assignment
mit-dov— "MIT Dover Spooler"; reference (blank — no RFC cited in IANA registry); assignee/contact Eliot Moss; dual-registered 91/tcp + 91/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry, line 251)- Range class
- well-known (0–1023) [Confirmed] — IANA registry
- Registration / modification date
- blank in the IANA registry — Unknown (not published; not invented) [Confirmed] — IANA CSV blank columns
- Related ports
- 91/tcp (same
mit-dovregistration); the historical research-network/printing cluster
Primary use
print-job spooling for the Xerox Dover laser printer; the MIT-MC spooler queued jobs and forwarded them via CHAOSNET/TCP to a Xerox Alto (SPRUCE) that drove the Dover hardware (late 1970s–early 1980s)
Other/historical software
the MIT-MC ITS-side Dover spooler (1982 era) and the Xerox Alto SPRUCE spooler; no current software uses this port
Security implications
SANS ISC reports only low-level opportunistic scanning (threat level green, 2026-06-25), no exploit/CVE for this port; third-party sites note historical malware use of port 91 but no verifiable family — treat any 91/udp inbound to a production host as anomalous and block it
Exposure risk
low inherent risk from the original (obsolete) protocol; an unexpected listening state on 91/udp most likely indicates misconfiguration, a backdoor, or a decoy
Typically seen on
nothing legitimate today; an open 91/udp is an anomaly worth investigating
- Modern usage
- none — the Dover/MIT spooler infrastructure is obsolete; 91/udp carries no legitimate modern service [Likely] — speedguide.net/port.php?port=91
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| mit-dov | UDP | MIT Dover Spooler | 0.05% |
| mit-dov | TCP | MIT Dover Spooler | 0.01% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.