TCP Port 513 – login

TCP Port 513 – login

About TCP Port 513

Port 513 is registered with the Internet Assigned Numbers Authority (IANA) for login. The IANA description reads: ‘remote login a la telnet; automatic authentication performed based on priviledged port numbers and distributed data bases which identify "authentication domains"’. This port appears in 8 IDS rules and does not have notable malware activity indicators in our data.

IDS Rule References

8 IDS / security rules reference TCP port 513. Presence in IDS rules does not mean traffic on this port is malicious. These are patterns security tools monitor.

Rule categories (top 4): attempted-admin (3), bad-unknown (2), unsuccessful-user (2), attempted-user (1).

Sample rule descriptions for TCP port 513:

  • PROTOCOL-SERVICES rlogin LinuxNIS
  • PROTOCOL-SERVICES rlogin bin
  • PROTOCOL-SERVICES rlogin echo++
  • PROTOCOL-SERVICES Unix rlogin froot parameter root access attempt
  • PROTOCOL-SERVICES rlogin login failure

Data Sources

This information is compiled from: IANA Service Name and Transport Protocol Port Number Registry, Emerging Threats Open Ruleset (BSD 2-Clause / GPLv2 per SID range), and Snort Community Rules (GPLv2).

© 2002-2026 AuditMyPC.com