Network port detail · UDP/TCP

93

Dcp
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No port-specific CVE or malware family is corroborated across mainstream trojan-port reference lists (Gary Kessler's Bad Ports, Trend Micro) that were checked. One low-authority ports-directory site claimed historical trojan/malware use without a citable source or incident — treated as unverified, not fact. Because the port has no confirmed legitimate modern service and no verifiable spec, a listener on TCP/93 is effectively unidentified and should be treated as anomalous and investigated. RFC 1010 (Assigned Numbers, 1987) historically listed the dcp/93 assignment but is an inventory document, not a protocol spec or the formal IANA Reference — the Reference field stays blank.
// analyst note
A registered-but-undocumented port. An open port 93 has no confirmed legitimate modern use and no verifiable spec — treat as anomalous and investigate rather than assume benign; do not repeat the unsourced "trojan port" claim as fact.
[ 01 ] — Context

About port 93/tcp.

Updated  ·  Confidence: Medium

Port 93/tcp is registered with IANA as dcp with the description "Device Control Protocol," contact Daniel Tappan, and a blank reference field. The assignment is dual-registered — port 93 carries the identical dcp / "Device Control Protocol" service data on both TCP and UDP, with the same contact and every remaining registry column (registration date, modification date, reference, service code, unauthorized-use-reported, assignment notes) left blank as-is in the registry. Unlike port 1's tcpmux, there is no surviving public protocol specification for "Device Control Protocol": no RFC is cited in the IANA Reference field, and no dedicated protocol-spec RFC or widely known reference implementation is verifiable through IANA or IETF sources. RFC 1010 ("Assigned Numbers," 1987) historically listed the dcp/93 assignment as part of the early Assigned Numbers lineage, but it is an inventory document, not a protocol specification, and it is not the registry's formal Reference — so the Reference field stays blank rather than being backfilled with RFC 1010. For an analyst the practical reality is that port 93 has no confirmed modern legitimate service and no verifiable spec, so any listener found on TCP/93 during a scan is effectively unidentified and should be treated as anomalous and investigated rather than assumed benign. Port 93 does not appear on mainstream trojan/malware port reference lists (Gary Kessler's Bad Ports list, Trend Micro trojan-port documentation) that were checked, so no specific malware family or CVE is corroborated for this port; one low-authority ports-directory site asserted historical trojan/malware use without citing a source or incident, and that claim is treated here as unverified rather than repeated as fact. The honest characterization is a registered-but-effectively-undocumented port: the name and assignment persist, IANA has not deprecated the entry, but there is no observed current use.

IANA assignment
dcp — "Device Control Protocol"; reference (blank — no RFC cited in IANA registry); contact Daniel Tappan; dual-registered 93/tcp + 93/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (local cached CSV lines 254–255)
Range class
well-known (0–1023) [Confirmed]
Registration / modification dates
Unknown — blank in the registry, not fabricated [Confirmed] — cached IANA CSV
Related ports
adjacent well-known assignments; contrast documented control-plane services with published specs

Primary use

registered as Device Control Protocol, but no surviving public protocol specification is verifiable

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Common software

Unknown — no modern software or service confirmed to bind TCP/93 for the registered dcp purpose (not confirmed deprecated, just unobserved) [Unknown]

Security implications

no port-specific CVE or malware family corroborated across mainstream trojan-port lists checked; one low-authority ports-directory claim of trojan use is unverified; a listener on TCP/93 has no confirmed legitimate modern use, so treat as anomalous and investigate

[Likely] — https://www.garykessler.net/library/bad_ports.html

Typically seen on

Unknown — no confirmed common deployment; any observed listener is effectively unidentified

Reference / RFC
blank — no RFC cited; RFC 1010 (Assigned Numbers, 1987) historically listed the dcp/93 assignment but is an inventory doc, not the formal Reference field or a protocol spec, and is NOT backfilled here [Confirmed] — https://datatracker.ietf.org/doc/html/rfc1010
Analyst note
A registered-but-undocumented port. An open port 93 has no confirmed legitimate modern use and no verifiable spec — treat as anomalous and investigate rather than assume benign; do not repeat the unsourced "trojan port" claim as fact.
[ 02 ] — Context

About port 93/udp.

Updated  ·  Confidence: Medium

Port 93/udp is registered with IANA under the service name dcp, described as "Device Control Protocol," with Daniel Tappan named as both assignee and contact of record. The entry is dual-registered: 93/tcp carries the identical service name, description, and assignee, so this is a paired TCP/UDP reservation rather than a UDP-only assignment. The IANA reference field is blank — no RFC or public specification is cited in the registry, and no surviving primary specification for a "Device Control Protocol" on this port could be located. That absence matters for how an analyst should read the port: dcp is best characterized as a legacy, name-only reservation with no documented wire format, no known reference implementation, and no widely deployed client or server software that defaults to it in current (2026) vendor or open-source documentation. In practice, port 93 behaves on modern networks much like an unassigned port — the assignment exists on paper but sees no confirmed legitimate traffic. Some low-authority aggregator sites (SpeedGuide, ports.my-addr.com, and similar) assert historical trojan or scanning activity on this port, and one secondary source suggests a "1987 / RFC 1010"-era origin, but none of these claims could be corroborated against a primary source, so they are recorded here as unverified context rather than fact. For an analyst, the honest posture is that both the modern-usage picture and the exposure/abuse picture for port 93 are effectively unknown: the registry name is solid, everything downstream of it is not.

IANA assignment
dcp — "Device Control Protocol"; reference (blank — no RFC cited in IANA registry); assignee/contact Daniel Tappan; dual-registered 93/tcp + 93/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)
Range class
well-known (0–1023) [Confirmed]
Registration date
Unknown — IANA's port registry carries no assignment/modification date field for this entry; a secondary "1987 / RFC 1010" claim could not be corroborated and is not asserted [Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Related ports
93/tcp (identical dcp dual registration, same assignee/contact) [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry

Primary use

legacy name-only reservation; no published RFC or surviving public specification, so functionally dormant on modern networks

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Common software

none identified — no widely deployed client/server defaults to or documents port 93 in current vendor/open-source docs

[Likely] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml
Security / exposure implications
Unknown — no citable primary or reputable source found for port-93-specific scanning, honeypot, or malware activity; unsourced aggregator trojan claims (SpeedGuide, ports.my-addr.com) are not corroborated and are not reported as fact [Unknown]
Analyst note
Registry name is solid; modern usage and abuse data are effectively unknown. Treat an open port 93 as an anomaly to investigate on its own merits rather than mapping it to a documented service.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
dcp UDP Device Control Protocol 0.08%
dcp TCP Device Control Protocol 0.00%
IANA name
dcp
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.