Port 11Systat

Systat is a legacy network service running on port 11, historically used to provide information about active users logged into a system. Initially part of the suite of early Internet services, it queried the system's status and relayed basic data about logged-in accounts. Today, it is primarily obsolete and carries significant security risks..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
10,551

rank 415 of 993 · top 42%

Technical Details

what runs on :11

The Systat protocol was defined in RFC 866 and ran primarily over TCP and UDP port 11. It was implemented on early UNIX systems as part of the BSD r-services suite to provide basic status information of users currently logged into a machine. This lightweight protocol responds with a plaintext list of logged-in users and their terminal information when queried.

Despite its simplicity, Systat served as an important administrative tool in the early days of network management, allowing system administrators to remotely monitor logged-in sessions without needing full shell access. It helped foster collaborative environments by enabling users to see who else was active on multi-user systems.

However, with the advent of more secure and feature-rich solutions (such as SSH and SNMP) and the protocol's inherent lack of access controls or encryption, Systat has fallen out of favor. Most modern systems disable this service by default due to security concerns and limited practical value.

Security Information

exposure of :11

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Due to its plaintext nature, data sent over Systat can be intercepted, exposing active user information.
  • Attackers can perform reconnaissance on users logged in, aiding social engineering or brute-force attacks targeting known usernames.
  • The lack of authentication allows any remote party to access its information, potentially revealing sensitive user activity.
  • Historically abused in network mapping and enumeration phases of attacks.

Common Mitigations:

  • Disable the Systat service entirely where it is unnecessary, which is standard best practice today.
  • Implement strict firewall rules blocking inbound and outbound traffic on port 11.
  • Use access controls and network segmentation to isolate legacy systems that might still require Systat.
  • Replace any legacy usages with secure, authenticated monitoring tools that provide similar capabilities with built-in encryption.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted