Port 2104Zephyr Hostmanager
Port 2104 is primarily used by the Zephyr Notification Service component, Hostmanager, within MIT's Project Athena environment. It facilitates the delivery of real-time notifications and messaging services among users and systems, supporting both TCP and UDP protocols. Despite being a legacy system, Zephyr remains a key technology within educational campuses and research environments to provide alerts and collaboration notifications..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 11,000
2 transports registered
payload readable on path
registered with iana
caution
rank 391 of 993 · top 39%
Technical Details
what runs on :2104Zephyr is a real-time messaging and notification service originally developed as part of MIT's Project Athena. The Zephyr system allows users and applications to exchange instant notifications across distributed computing environments. It is designed with a publish-subscribe model, where 'clients' subscribe to certain message classes and instances, receiving notifications relevant to their interests.
Port 2104 is associated with the Zephyr Hostmanager (zephyr-hm) component, which coordinates the delivery of these notifications within the network. The Hostmanager handles routing messages, managing subscriptions, presence information, and maintaining session state. Both TCP and UDP are used for communication depending on the reliability and latency needs of the particular operation.
Architecturally, Zephyr operates over standard IP networking stacks and typically integrates with Kerberos for authentication. Despite age, Zephyr's publish-subscribe and notification capabilities inspired messaging patterns still in use today. Modern systems may use it in legacy environments or for compatibility with existing infrastructure.
Security Information
exposure of :2104risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common Vulnerabilities:
- Zephyr is a legacy protocol that lacks built-in encryption, making it susceptible to eavesdropping and message interception.
- Because presence and subscription information may be transmitted in plaintext, attackers might gather intelligence for social engineering or further attacks.
- Potential buffer overflows or denial of service vulnerabilities in older, unmaintained Zephyr service implementations.
Common Mitigations:
- Deploy Zephyr within isolated or trusted network segments to reduce exposure to unauthorized actors.
- Use network-layer encryption methods such as VPNs or SSH tunnels to protect message contents.
- Keep Zephyr software updated and, if possible, patch or replace insecure components.
- Leverage strong Kerberos authentication to limit unauthorized message submission or subscription.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted