Network port detail · UDP/TCP

95

Supdup
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No port-95/SUPDUP-specific Shodan/Censys exposure counts, honeypot data, or CVE history located in this pass. Mass internet scanners enumerate the full well-known range (port 95 included) but no port-95-specific measurement was found. Given the protocol's legacy/inactive status, expected real-world exposure is presumed very low, but this is an inference, not a sourced measurement (Unknown). A responsive port 95 is more plausibly an anomaly, decoy, or mislabeled service than a genuine SUPDUP endpoint.
// analyst note
A responsive port 95 is statistically rare; treat as a historical fingerprint or anomaly and investigate rather than assume a live SUPDUP service.
[ 01 ] — Context

About port 95/tcp.

Updated  ·  Confidence: Medium

Port 95/tcp is registered with IANA as supdup with the description "SUPDUP," assignee and contact both listed as Mark Crispin, and blank Registration Date, Modification Date, and Reference columns in the local Service Name and Transport Protocol Port Number Registry snapshot; the same service name is dual-registered on 95/tcp and 95/udp with identical fields. The IANA registry cites no reference for this port (Reference column blank). SUPDUP is nonetheless specified in RFC 734 ("SUPDUP Protocol," M. Crispin, October 1977) as the protocol's own historical specification — a separate fact from the (blank) IANA Reference column. SUPDUP — the name is commonly read as a "Superior Display Update Protocol" descendant — is a legacy remote-display terminal protocol from the ARPANET/ITS era, designed at MIT as a more capable alternative to plain TELNET for driving a remote user's display terminal with cursor-addressing and screen-update semantics tuned to the wide variety of terminal hardware of the time. A follow-on, RFC 747 ("Recent Extensions to the SUPDUP Protocol"), extends it. For an analyst, port 95 is almost entirely a historical curiosity: no actively maintained SUPDUP client or server software was found in this pass, and a registry listing does not imply active deployment. No port-95-specific Shodan/Censys exposure counts, honeypot data, or CVE history were located, so real-world exposure is presumed very low but is treated as Unknown rather than a sourced measurement — a responsive port 95 today is more plausibly a mislabeled service, a decoy, or an anomaly than a genuine SUPDUP endpoint, and is worth investigating on those grounds.

IANA assignment
supdup — "SUPDUP"; assignee and contact both Mark Crispin; dual-registered 95/tcp + 95/udp; Registration Date, Modification Date, Reference, Service Code, Unauthorized Use Reported, and Assignment Notes columns all blank in the source
[Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (tcp), :259 (udp)
IANA reference / RFC
IANA Reference column is blank — no reference is cited in the registry for this port [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry. The protocol itself is specified in RFC 734 ("SUPDUP Protocol," M. Crispin, October 1977), IETF-classified Legacy/historic, independent of the IANA Reference field; RFC 747 extends it
[Confirmed] — https://datatracker.ietf.org/doc/html/rfc734
Range class
well-known (0–1023)
Registration / allocated date
blank in the source registry; no IANA "date registered" field for this legacy assignment. Do NOT confuse with the RFC 734 publication date (Oct 1977, an authorship date, not a registry allocation event) [Unknown] — the IANA Service Name and Transport Protocol Port Number Registry
Related ports
TELNET (23/tcp) as the contemporary alternative it competed with; 95/udp (same supdup registration)

Primary use

legacy remote-display/terminal protocol (ARPANET/ITS era; MIT), a more capable TELNET alternative with cursor-addressing and screen-update semantics; unrelated to modern RDP/VNC/X11

[Confirmed] — https://datatracker.ietf.org/doc/html/rfc734

Common software today

effectively none — no actively maintained SUPDUP client or server found; treated as historical/legacy

[Unknown] — https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Typically seen on

no evidence of current legitimate deployment; a responsive port 95 is an anomaly / possible decoy or mislabeled service

Security / exposure
no port-95-specific Shodan/Censys counts, honeypot data, or CVEs found this pass; mass scanners enumerate the full well-known range (so port 95 is included) but no port-95 measurement located; expected exposure very low by inference [Unknown] — https://help.shodan.io/the-basics/on-demand-scanning
Analyst note
A responsive port 95 is statistically rare; treat as a historical fingerprint or anomaly and investigate rather than assume a live SUPDUP service.
[ 02 ] — Context

About port 95/udp.

Updated  ·  Confidence: High

Port 95/udp is registered with IANA as supdup with the description "SUPDUP," contact/assignee Mark Crispin, and a blank reference field. SUPDUP — the SUperDUPer Display Protocol — is a device-independent, terminal-aware remote-display protocol from the PDP-10/ITS (Incompatible Timesharing System) world at MIT, functionally analogous to Telnet but with the terminal's display characteristics negotiated so the server can drive the screen intelligently rather than treating it as a dumb stream. It is specified in RFC 734 ("SUPDUP Protocol," Mark R. Crispin, dated October 7, 1977 in the document itself). The decimal port 95 traces directly to the RFC, which states the SUPDUP server listens on "socket 137 octal" — 137 octal equals 95 decimal — reflecting the octal socket-numbering convention of the PDP-10 era. As a protocol from 1977 it predates modern transport security: RFC 734 defines no encryption and no authentication layer of its own, so any SUPDUP traffic is unencrypted by design. For an analyst the practical importance today is almost entirely historical and as an anomaly signal. SUPDUP was implemented on MIT ITS and related PDP-10 timesharing systems in the 1970s–80s; no actively maintained modern client or server implementation was identified, and the nmap-services dataset records an observed open-frequency of ≈ 0.000379 for 95/udp — very low, roughly 4 in 10,000 scanned hosts, against ≈ 0.000025 for 95/tcp — but no primary, dated measurement of real-world exposure (e.g. Shodan/Censys counts or honeypot telemetry) was found. Secondary port-lookup aggregators characterize it qualitatively as unencrypted and a scanner target, but those are non-authoritative and carry no sourced numbers, so exposure beyond the nmap-services figure is recorded as Unknown rather than asserted. supdup is confirmed dual-registered on both 95/tcp and 95/udp in the canonical IANA registry, with identical assignee/contact (Mark Crispin) on both rows. A responsive port 95 today is therefore statistically rare and worth investigating as a legacy artifact, a decoy, or a mislabeled service rather than a normal production service.

IANA assignment
supdup — "SUPDUP"; reference (blank — no RFC cited in IANA registry); assignee/contact Mark Crispin [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (local cache the IANA Service Name and Transport Protocol Port Number Registry; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)
Range class
well-known (0–1023)
Prevalence
nmap-services observed open-frequency 95/udp ≈ 0.000379 — very low (roughly 4 in 10,000 scanned hosts in the nmap-services sample); the paired 95/tcp row is rarer still at ≈ 0.000025 [Confirmed] — nmap-services dataset. Beyond that figure, no primary dated exposure measurement (Shodan/Censys counts, honeypot telemetry) was located for 95/udp; aggregator "scanner target" characterizations remain non-authoritative and unsourced [Unknown]
Related ports
Telnet (23) as the general-purpose terminal analogue; 95/tcp (same supdup registration); the small-services and legacy-terminal cluster

Primary use

SUPDUP (SUperDUPer Display Protocol) — device-independent, terminal-aware remote-display protocol from MIT ITS / PDP-10, analogous to Telnet but display-aware; defined in RFC 734 (M. Crispin, Oct 7 1977)

[Confirmed] — RFC 734 (https://www.rfc-editor.org/rfc/rfc734)

Other/unofficial uses

none identified; no actively maintained modern client/server implementation found [Unknown]

Security implications

SUPDUP as specified predates modern transport security — RFC 734 defines no encryption or authentication, so traffic is unencrypted by design [Likely — structural fact from RFC 734, single primary source] — RFC 734. Claims that it is "superseded by SSH" or "actively targeted" come only from non-authoritative aggregators and are not confirmed [Unknown]

Typically seen on

historically MIT ITS / PDP-10 timesharing hosts; otherwise an anomaly / possible decoy or mislabeled service

Port-number origin
RFC 734 specifies the server on "socket 137 octal"; 137 octal = 95 decimal [Confirmed] — RFC 734
TCP dual-registration
Confirmed — canonical registry row 258 carries 95/tcp supdup with the same assignee/contact (Mark Crispin) as the 95/udp row (259); supdup is dual-registered on both 95/tcp and 95/udp [Confirmed] — the IANA Service Name and Transport Protocol Port Number Registry (tcp), :259 (udp)
Analyst note
An open port 95 is statistically rare and historically a PDP-10/ITS SUPDUP artifact — treat as a legacy/anomaly signal and investigate; legitimate modern use is unlikely.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
supdup UDP 0.04%
supdup TCP BSD supdupd(8) 0.00%
IANA name
supdup
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.