96
Summary
- // if you see it open
- No CVE, known malware family, or honeypot report found naming port 96 specifically. Low-tier aggregator listings are generic registry references (auditmypc.com explicitly states no virus/trojan is associated). Because DIXIE is obsolete and essentially unimplemented today, traffic on port 96 is far more plausibly scanner noise, a research probe, or a misconfigured/unrelated service than legitimate DIXIE traffic.
- // analyst note
- DIXIE is effectively dead. Treat a responsive port 96 as anomalous — investigate as scanner noise, a decoy, or an unrelated service rather than genuine DIXIE traffic.
About port 96/tcp.
Port 96/tcp is registered with IANA as dixie with the description "DIXIE Protocol Specification," assignee and contact both Tim Howes, and a blank reference field in the machine-readable registry (dual-registered on TCP and UDP with identical entries). DIXIE is a lightweight client-access protocol for OSI X.500 directory services, created around 1990 at the University of Michigan by Tim Howes, Mark Smith, and Bryan Beecher and specified in RFC 1249 (August 1991). It let a TCP/UDP-based client query an X.500 Directory Service without implementing the full ISO transport and presentation stack that native DAP (Directory Access Protocol) demanded; RFC 1249 states plainly that the DIXIE server listens on port 96 for both UDP packets and TCP connections. DIXIE matters historically as the direct precursor to LDAP — Howes and colleagues generalized the DIXIE approach into the Lightweight Directory Access Protocol, which superseded it entirely by the mid-1990s and moved directory access to port 389. For an analyst, DIXIE is effectively extinct: no modern software distribution ships a DIXIE server or client, and the only implementation traceable in the record is the original University of Michigan code tied to RFC 1249. Because the protocol is unimplemented in practice, any traffic seen on port 96 today is far more plausibly scanner noise, a research probe across the full port range, or a misconfigured/unrelated service than legitimate DIXIE use. The IANA reference field for this old pre-1992 assignment is blank in the structured registry even though RFC 1249 is the documented specification, so the reference stays blank here per the no-fabrication rule while RFC 1249 is cited in prose. No CVE, malware family, or honeypot report was found naming port 96 specifically.
- IANA assignment
dixie— "DIXIE Protocol Specification"; reference (blank — no RFC cited in the machine-readable IANA registry); assignee/contact Tim Howes; dual-registered 96/tcp + 96/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (local cached the IANA Service Name and Transport Protocol Port Number Registry, lines 260–261; https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml)- Range class
- well-known (0–1023) [Confirmed]
- Current status
- obsolete/extinct in practice; fully superseded by LDAP by the mid-1990s; no modern software found implementing DIXIE as of 2026 [Likely] — https://en.wikipedia.org/wiki/DIXIE
- Related ports
- X.500/directory lineage — LDAP 389/tcp (and LDAPS 636); DIXIE is the historical precursor
Primary use
lightweight client-access protocol for OSI X.500 directory services; RFC 1249 (Howes, Smith, Beecher; University of Michigan; August 1991); the DIXIE server listens on port 96 for both UDP and TCP
Common software
Unknown — no current implementation identified; only the original circa-1990 University of Michigan server/client tied to RFC 1249 is traceable
Security implications
no CVE, known malware family, or honeypot report found naming port 96 specifically; low-tier aggregator listings are generic registry references (auditmypc.com explicitly states no virus/trojan association); given DIXIE's obsolescence, observed traffic is more likely scanner noise than legitimate use
Typically seen on
nothing in modern production; an open port 96 is an anomaly (scanner noise, misconfiguration, or unrelated service)
- Historical significance
- direct precursor to LDAP; generalized by Howes et al. into LDAP, which superseded DIXIE and moved to port 389 [Confirmed] — https://en.wikipedia.org/wiki/DIXIE
- Analyst note
- DIXIE is effectively dead. Treat a responsive port 96 as anomalous — investigate as scanner noise, a decoy, or an unrelated service rather than genuine DIXIE traffic.
About port 96/udp.
Port 96/udp is registered with IANA under the service name dixie, description "DIXIE Protocol Specification," with contact/assignee Tim Howes and a blank reference field; the same name and description are dual-registered on 96/tcp with identical field values. DIXIE (the DIXIE Information eXchange) was an experimental, lightweight TCP/IP protocol developed at the University of Michigan by Tim Howes, Mark Smith, and Bryan Beecher and documented in RFC 1249 (August 1991). It let ordinary TCP/IP clients query X.500 directory services through a DIXIE-to-DAP gateway without implementing the full, heavyweight OSI protocol stack that native X.500 Directory Access Protocol demanded. Historically the port matters mainly for lineage rather than live traffic: DIXIE is the direct precursor to LDAP (the Lightweight Directory Access Protocol), which superseded it around 1993 and carried forward the same "lightweight TCP/IP client to X.500 directory" idea on port 389. Note that although RFC 1249 is unmistakably the "DIXIE Protocol Specification" document by name, IANA's own machine-readable registry does not populate a Reference for this entry, so the IANA Reference column is recorded blank rather than back-filled with the RFC. For an analyst, port 96 is a dormant legacy assignment: no current daemon, product, or library was found that binds it under the dixie name, and no CVE, malware family, or named scanning campaign is specifically tied to it. Generic "trojans have used this port" boilerplate appears on port-aggregator sites but recurs across many low-numbered ports and is not a verifiable, port-specific claim, so any inbound UDP/96 is more plausibly opportunistic scanning or backscatter than protocol-specific abuse.
- IANA assignment
dixie— "DIXIE Protocol Specification"; reference (blank — no RFC cited in IANA registry); contact/assignee Tim Howes; dual-registered 96/tcp + 96/udp [Confirmed] — IANA Service Name and Transport Protocol Port Number Registry (raw .txt + xhtml search agreed exactly)- Range class
- well-known (0–1023) [Confirmed]
- Registration / modification dates
- blank in the source registry row (not recorded by IANA for this entry) → Unknown [Confirmed-blank]
- Related ports
- 389 (LDAP, the successor); other X.500 / directory-service ports
Primary use
lightweight TCP/IP client access to X.500 directory services via a DIXIE-to-DAP gateway; documented in RFC 1249 (Howes/Smith/Beecher, University of Michigan, August 1991)
Protocol lineage
direct precursor to LDAP, which superseded DIXIE circa 1993
Common software
none identified — no current daemon, product, or library found binding 96/udp under the dixie name; DIXIE was obsoleted by LDAP by the mid-1990s [Unknown]
Security implications
no CVE, malware family, Shodan/Censys tag, or named advisory specifically tied to 96/udp; generic aggregator "trojan" boilerplate is not port-specific and is treated as unverified
Typically seen on
nothing in current production; a legacy/dormant assignment
- Analyst note
- A responsive 96/udp is statistically rare; legitimate DIXIE use is effectively extinct, so treat inbound UDP/96 as opportunistic scanning or backscatter absent other evidence.
Service assignments.
| Name | Protocol | Description | Open frequency |
|---|---|---|---|
| dixie | UDP | DIXIE Protocol Specification | 0.09% |
| dixie | TCP | DIXIE Protocol Specification | 0.00% |
Service assignments from the IANA Service Name and Transport Protocol Port Number Registry, with open-frequency data from nmap-services.