Network port detail · UDP/TCP

96

Dixie
Protocol(s)
UDP/TCP
Range
System (0-1023)

Summary

// if you see it open
No CVE, known malware family, or honeypot report found naming port 96 specifically. Low-tier aggregator listings are generic registry references (auditmypc.com explicitly states no virus/trojan is associated). Because DIXIE is obsolete and essentially unimplemented today, traffic on port 96 is far more plausibly scanner noise, a research probe, or a misconfigured/unrelated service than legitimate DIXIE traffic.
// analyst note
DIXIE is effectively dead. Treat a responsive port 96 as anomalous — investigate as scanner noise, a decoy, or an unrelated service rather than genuine DIXIE traffic.
[ 01 ] — Context

About port 96/tcp.

Updated  ·  Confidence: High

Port 96/tcp is registered with IANA as dixie with the description "DIXIE Protocol Specification," assignee and contact both Tim Howes, and a blank reference field in the machine-readable registry (dual-registered on TCP and UDP with identical entries). DIXIE is a lightweight client-access protocol for OSI X.500 directory services, created around 1990 at the University of Michigan by Tim Howes, Mark Smith, and Bryan Beecher and specified in RFC 1249 (August 1991). It let a TCP/UDP-based client query an X.500 Directory Service without implementing the full ISO transport and presentation stack that native DAP (Directory Access Protocol) demanded; RFC 1249 states plainly that the DIXIE server listens on port 96 for both UDP packets and TCP connections. DIXIE matters historically as the direct precursor to LDAP — Howes and colleagues generalized the DIXIE approach into the Lightweight Directory Access Protocol, which superseded it entirely by the mid-1990s and moved directory access to port 389. For an analyst, DIXIE is effectively extinct: no modern software distribution ships a DIXIE server or client, and the only implementation traceable in the record is the original University of Michigan code tied to RFC 1249. Because the protocol is unimplemented in practice, any traffic seen on port 96 today is far more plausibly scanner noise, a research probe across the full port range, or a misconfigured/unrelated service than legitimate DIXIE use. The IANA reference field for this old pre-1992 assignment is blank in the structured registry even though RFC 1249 is the documented specification, so the reference stays blank here per the no-fabrication rule while RFC 1249 is cited in prose. No CVE, malware family, or honeypot report was found naming port 96 specifically.

IANA assignment
dixie — "DIXIE Protocol Specification"; reference (blank — no RFC cited in the machine-readable IANA registry); assignee/contact Tim Howes; dual-registered 96/tcp + 96/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (local cached the IANA Service Name and Transport Protocol Port Number Registry, lines 260–261; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)
Range class
well-known (0–1023) [Confirmed]
Current status
obsolete/extinct in practice; fully superseded by LDAP by the mid-1990s; no modern software found implementing DIXIE as of 2026 [Likely] — https://en.wikipedia.org/wiki/DIXIE
Related ports
X.500/directory lineage — LDAP 389/tcp (and LDAPS 636); DIXIE is the historical precursor

Primary use

lightweight client-access protocol for OSI X.500 directory services; RFC 1249 (Howes, Smith, Beecher; University of Michigan; August 1991); the DIXIE server listens on port 96 for both UDP and TCP

[Confirmed] — https://www.rfc-editor.org/rfc/rfc1249.html

Common software

Unknown — no current implementation identified; only the original circa-1990 University of Michigan server/client tied to RFC 1249 is traceable

[Unknown] — https://www.rfc-editor.org/rfc/rfc1249.html

Security implications

no CVE, known malware family, or honeypot report found naming port 96 specifically; low-tier aggregator listings are generic registry references (auditmypc.com explicitly states no virus/trojan association); given DIXIE's obsolescence, observed traffic is more likely scanner noise than legitimate use

[Likely] — https://www.auditmypc.com/tcp-port-96.asp

Typically seen on

nothing in modern production; an open port 96 is an anomaly (scanner noise, misconfiguration, or unrelated service)

Historical significance
direct precursor to LDAP; generalized by Howes et al. into LDAP, which superseded DIXIE and moved to port 389 [Confirmed] — https://en.wikipedia.org/wiki/DIXIE
Analyst note
DIXIE is effectively dead. Treat a responsive port 96 as anomalous — investigate as scanner noise, a decoy, or an unrelated service rather than genuine DIXIE traffic.
[ 02 ] — Context

About port 96/udp.

Updated  ·  Confidence: High

Port 96/udp is registered with IANA under the service name dixie, description "DIXIE Protocol Specification," with contact/assignee Tim Howes and a blank reference field; the same name and description are dual-registered on 96/tcp with identical field values. DIXIE (the DIXIE Information eXchange) was an experimental, lightweight TCP/IP protocol developed at the University of Michigan by Tim Howes, Mark Smith, and Bryan Beecher and documented in RFC 1249 (August 1991). It let ordinary TCP/IP clients query X.500 directory services through a DIXIE-to-DAP gateway without implementing the full, heavyweight OSI protocol stack that native X.500 Directory Access Protocol demanded. Historically the port matters mainly for lineage rather than live traffic: DIXIE is the direct precursor to LDAP (the Lightweight Directory Access Protocol), which superseded it around 1993 and carried forward the same "lightweight TCP/IP client to X.500 directory" idea on port 389. Note that although RFC 1249 is unmistakably the "DIXIE Protocol Specification" document by name, IANA's own machine-readable registry does not populate a Reference for this entry, so the IANA Reference column is recorded blank rather than back-filled with the RFC. For an analyst, port 96 is a dormant legacy assignment: no current daemon, product, or library was found that binds it under the dixie name, and no CVE, malware family, or named scanning campaign is specifically tied to it. Generic "trojans have used this port" boilerplate appears on port-aggregator sites but recurs across many low-numbered ports and is not a verifiable, port-specific claim, so any inbound UDP/96 is more plausibly opportunistic scanning or backscatter than protocol-specific abuse.

IANA assignment
dixie — "DIXIE Protocol Specification"; reference (blank — no RFC cited in IANA registry); contact/assignee Tim Howes; dual-registered 96/tcp + 96/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (raw .txt + xhtml search agreed exactly)
Range class
well-known (0–1023) [Confirmed]
Registration / modification dates
blank in the source registry row (not recorded by IANA for this entry) → Unknown [Confirmed-blank]
Related ports
389 (LDAP, the successor); other X.500 / directory-service ports

Primary use

lightweight TCP/IP client access to X.500 directory services via a DIXIE-to-DAP gateway; documented in RFC 1249 (Howes/Smith/Beecher, University of Michigan, August 1991)

[Confirmed] — RFC 1249, Wikipedia (DIXIE)

Protocol lineage

direct precursor to LDAP, which superseded DIXIE circa 1993

[Confirmed] — Wikipedia (LDAP)

Common software

none identified — no current daemon, product, or library found binding 96/udp under the dixie name; DIXIE was obsoleted by LDAP by the mid-1990s [Unknown]

Security implications

no CVE, malware family, Shodan/Censys tag, or named advisory specifically tied to 96/udp; generic aggregator "trojan" boilerplate is not port-specific and is treated as unverified

[Unknown/Threat-reported] — auditmypc.com, speedguide.net (low-confidence disclaimer pattern)

Typically seen on

nothing in current production; a legacy/dormant assignment

Analyst note
A responsive 96/udp is statistically rare; legitimate DIXIE use is effectively extinct, so treat inbound UDP/96 as opportunistic scanning or backscatter absent other evidence.
// registry data

Service assignments.

2 entries
// IANA / nmap services registry
NameProtocolDescriptionOpen frequency
dixie UDP DIXIE Protocol Specification 0.09%
dixie TCP DIXIE Protocol Specification 0.00%
IANA name
dixie
Transport
TCP
Range
System (0-1023)

Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.