TCP Port 512 – exec
About TCP Port 512
Port 512 carries the IANA assignment for exec. The IANA description reads: ‘remote process execution; authentication performed using passwords and UNIX login names’. This port appears in 3 IDS rules and does not have notable malware activity indicators in our data.
IDS Rule References
3 IDS / security rules reference TCP port 512. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.
Rule categories (top 2): attempted-admin (2), unsuccessful-user (1).
Sample rule descriptions for TCP port 512:
- INDICATOR-COMPROMISE rexec username too long response
- PROTOCOL-SERVICES rexec username overflow attempt
- PROTOCOL-SERVICES rexec password overflow attempt
Data Sources
This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry and Snort Community Rules (GPLv2).
