Port 221Berkeley rlogind with SPX authentication
Berkeley rlogind remote-login service using SPX authentication on TCP and UDP port 221.
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 7/10
- lookups
- 0
2 transports registered
payload readable on path
registered with iana
risk
rank 993 of 5,288 · top 19%
also known as fln-spx
Technical Details
what runs on :221The registry assigns both TCP and UDP 221 to this service, although rlogind is fundamentally a session-oriented, byte-stream remote-login protocol and implementations would normally favor a connection-oriented transport. A Berkeley rlogin-style exchange typically begins with NUL-terminated local username, remote username, and terminal/speed fields, followed by bidirectional terminal data and control signaling; this variant adds SPX authentication. Standard Berkeley rlogin is commonly associated with TCP 513, so port 221 should be treated as a legacy or implementation-specific placement rather than the normal rlogin default.
Security Information
exposure of :221risk score
7/ 10risk
treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.
remote access averages 3.8 across 207 ports — this one sits 3.2 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
rlogin-style services are generally unencrypted and historically rely on host-based trust such as .rhosts rather than strong user authentication. An exposed listener can disclose terminal traffic and permit unauthorized remote access if its trust configuration is weak; it should not be exposed directly to the Internet and should be replaced or isolated behind a secure management channel.
Related Ports
the 8 most looked-up other ports in remote access — 207 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8000 | Intel Remote Desktop / Alternate HTTP Port | TCP | Web Services | safe | 84.3k |
| :8888 | D2GS Admin Console | TCP | Remote Access | caution | 83.7k |
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :8008 | IBM HTTP Server Admin | TCP | Web Services | caution | 58.3k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :23 | Telnet | TCP | Remote Access | caution | 34.8k |
risk mix of the 8 listed
- safe13%
- caution88%
0 of 8 encrypted