Network port detail · UDP/TCP

91

Mit-dov
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
SANS ISC shows background scanning of 91/tcp from distributed sources at a low/green threat level, consistent with opportunistic internet-wide scanning. No CVEs, named malware families, or confirmed backdoors are associated with this port. A third-party site (auditmypc.com) flags a historical trojan association but names no malware and provides no evidence — unverified.
// analyst note
A real MIT Dover spooler on port 91 would be extraordinary; an open 91 today is more plausibly a custom service or scan artifact than the registered service. The IANA reference field is blank.
[ 01 ] — Context

About port 91/tcp.

Updated  ·  Confidence: Medium

Port 91/tcp is registered with IANA as mit-dov with the description "MIT Dover Spooler," assignee Eliot Moss, and a blank reference field (dual-registered on TCP and UDP — 91/udp carries the same mit-dov name and description). The name traces to the Xerox Dover, a late-1970s Xerox PARC raster laser printer, and to MIT's print-spooling setup for it: through the early 1980s MIT ran a Dover spooler on its ITS (Incompatible Timesharing System) machines, queuing jobs that were ultimately driven to the printer via a Xerox Alto running the SPRUCE print software, with documents shipped over the Ethernet File Transfer Protocol (EFTP). The IANA service name mit-dov is a direct artifact of that history. For an analyst the practical reality is that this protocol is obsolete: the Dover printer, the Alto, and the ITS spooler are all museum-era technology, and no current commercial or open-source software is known to listen on port 91 for this purpose. The IANA registry cites no RFC for the assignment, so the reference column is genuinely blank rather than missing. SANS ISC data shows background scanning of 91/tcp from distributed sources at a low/green threat level, consistent with opportunistic internet-wide scanning rather than targeted exploitation; no CVEs, named malware families, or confirmed backdoors are tied to this port. One third-party site (auditmypc.com) flags a historical trojan association, but names no malware and offers no supporting evidence, so that claim is unverified. In practice an open port 91 today is far more likely to be an unrelated custom service squatting on the number than a real MIT Dover spooler.

IANA assignment
mit-dov — "MIT Dover Spooler"; reference (blank — no RFC cited in IANA registry); assignee Eliot Moss; dual-registered 91/tcp + 91/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry
Range class
well-known (0–1023) [Confirmed]
Registration date / modification date
blank in the IANA registry (genuine null, not missing) [Confirmed] — IANA registry
Related ports
the legacy/print and small-services neighborhood; contrast modern print protocols (e.g. 515 LPD, 631 IPP)

Primary use

print spooler for the Xerox Dover laser printer; MIT ran a Dover spooler on ITS in the early 1980s, driving the printer via a Xerox Alto (SPRUCE) over EFTP

[Likely] — IANA registry; MIT Interim Computer Museum blog (icm.museum/blog/?p=38); Wikipedia (Xerox Dover)

Common software

MIT ITS Dover spooler and Xerox Alto SPRUCE host — all legacy/historical; no current software known to use this port

[Likely] — MIT Interim Computer Museum blog

Security implications / scanning

SANS ISC shows active background scanning of 91/tcp from distributed sources at green/low threat level; no CVEs, named malware, or confirmed backdoors. An auditmypc.com trojan flag is unsubstantiated (no named malware) — treat as unverified

[Likely] — SANS ISC (isc.sans.edu/port.html?port=91); auditmypc.com

Typically seen on

historically MIT ITS hosts; today, an anomaly or an unrelated custom service reusing the number

Analyst note
A real MIT Dover spooler on port 91 would be extraordinary; an open 91 today is more plausibly a custom service or scan artifact than the registered service. The IANA reference field is blank.
[ 02 ] — Context

About port 91/udp.

Updated  ·  Confidence: High

Port 91/udp is registered with IANA under the service name mit-dov, described as "MIT Dover Spooler," with assignee and contact listed as Eliot Moss and a blank reference field. The registration is dual: both 91/tcp and 91/udp carry the same mit-dov service name and description. The protocol is a relic of late-1970s and early-1980s research-network printing. The Dover was a Xerox PARC laser printer (only on the order of thirty-five units were built) deployed at institutions such as the MIT AI Lab and Stanford; the MIT spooler queued print jobs and forwarded them — over CHAOSNET/TCP through a gateway — to a Xerox Alto machine running the SPRUCE spooler, which in turn drove the Dover hardware. Port 91 was registered to carry that spooling traffic over the network. None of this survives in modern software: the Dover and its associated MIT spooler infrastructure are long obsolete, and 91/udp sees no meaningful legitimate traffic on contemporary networks. For an analyst the port's relevance today is almost entirely as an anomaly indicator. SANS ISC shows only low-level opportunistic, internet-wide scanning on port 91 (threat level green as of 2026-06-25), with no documented exploit or CVE targeting it. Some third-party security references note historical malware association with port 91, but no specific, verifiable trojan family is documented in the sources retrieved, so that claim is tagged Likely rather than treated as fact. Because the port carries no legitimate modern service, any inbound traffic on 91/udp to a production host is anomalous and most plausibly reflects misconfiguration, a backdoor, or a decoy rather than a real service — and warrants blocking.

IANA assignment
mit-dov — "MIT Dover Spooler"; reference (blank — no RFC cited in IANA registry); assignee/contact Eliot Moss; dual-registered 91/tcp + 91/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry, line 251)
Range class
well-known (0–1023) [Confirmed] — IANA registry
Registration / modification date
blank in the IANA registry — Unknown (not published; not invented) [Confirmed] — IANA CSV blank columns
Related ports
91/tcp (same mit-dov registration); the historical research-network/printing cluster

Primary use

print-job spooling for the Xerox Dover laser printer; the MIT-MC spooler queued jobs and forwarded them via CHAOSNET/TCP to a Xerox Alto (SPRUCE) that drove the Dover hardware (late 1970s–early 1980s)

[Likely] — en.wikipedia.org/wiki/Xerox_Dover, icm.museum/blog/?p=38

Other/historical software

the MIT-MC ITS-side Dover spooler (1982 era) and the Xerox Alto SPRUCE spooler; no current software uses this port

[Likely] — icm.museum/blog/?p=38

Security implications

SANS ISC reports only low-level opportunistic scanning (threat level green, 2026-06-25), no exploit/CVE for this port; third-party sites note historical malware use of port 91 but no verifiable family — treat any 91/udp inbound to a production host as anomalous and block it

[Likely] — isc.sans.edu/data/port/91, auditmypc.com/udp-port-91.asp

Exposure risk

low inherent risk from the original (obsolete) protocol; an unexpected listening state on 91/udp most likely indicates misconfiguration, a backdoor, or a decoy

[Likely] — isc.sans.edu/data/port/91

Typically seen on

nothing legitimate today; an open 91/udp is an anomaly worth investigating

Modern usage
none — the Dover/MIT spooler infrastructure is obsolete; 91/udp carries no legitimate modern service [Likely] — speedguide.net/port.php?port=91
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
mit-dov UDP MIT Dover Spooler 0.05%
mit-dov TCP MIT Dover Spooler 0.01%
IANA name
mit-dov
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.