Port 11Systat
Systat is a legacy network service running on port 11, historically used to provide information about active users logged into a system. Initially part of the suite of early Internet services, it queried the system's status and relayed basic data about logged-in accounts. Today, it is primarily obsolete and carries significant security risks..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 10,551
2 transports registered
payload readable on path
registered with iana
caution
rank 415 of 993 · top 42%
Technical Details
what runs on :11The Systat protocol was defined in RFC 866 and ran primarily over TCP and UDP port 11. It was implemented on early UNIX systems as part of the BSD r-services suite to provide basic status information of users currently logged into a machine. This lightweight protocol responds with a plaintext list of logged-in users and their terminal information when queried.
Despite its simplicity, Systat served as an important administrative tool in the early days of network management, allowing system administrators to remotely monitor logged-in sessions without needing full shell access. It helped foster collaborative environments by enabling users to see who else was active on multi-user systems.
However, with the advent of more secure and feature-rich solutions (such as SSH and SNMP) and the protocol's inherent lack of access controls or encryption, Systat has fallen out of favor. Most modern systems disable this service by default due to security concerns and limited practical value.
Security Information
exposure of :11risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common Vulnerabilities:
- Due to its plaintext nature, data sent over Systat can be intercepted, exposing active user information.
- Attackers can perform reconnaissance on users logged in, aiding social engineering or brute-force attacks targeting known usernames.
- The lack of authentication allows any remote party to access its information, potentially revealing sensitive user activity.
- Historically abused in network mapping and enumeration phases of attacks.
Common Mitigations:
- Disable the Systat service entirely where it is unnecessary, which is standard best practice today.
- Implement strict firewall rules blocking inbound and outbound traffic on port 11.
- Use access controls and network segmentation to isolate legacy systems that might still require Systat.
- Replace any legacy usages with secure, authenticated monitoring tools that provide similar capabilities with built-in encryption.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted