Port 311Mac OS X Server Admin

Port 311 was historically used by Mac OS X Server's Admin tool, which provided a web-based management interface for AppleShare IP services. This allowed system administrators to configure and control server-side functions, including file sharing, web services, and user management, from any standard web browser with appropriate authentication. Over time, its utility diminished as Apple transitioned to new server management paradigms..

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
23,722

rank 79 of 993 · top 8%

Technical Details

what runs on :311

Port 311, known as the Mac OS X Server Admin port, was integral to managing a Mac server via a web-based interface. This port facilitated the administration of AppleShare IP, allowing remote configuration of various network services directly through HTTP connections. Interaction typically involved authenticated web sessions using proprietary protocols atop HTTP to provide control mechanisms tailored for Apple’s server solutions.

The service hosted on port 311 was tightly integrated with Mac OS X Server's suite of tools, supporting network file sharing, web hosting, mail services, and user and group management. Administrators accessed these tools via a browser interface or Apple's dedicated client applications, which communicated over this port. It was designed to simplify server oversight, easing tasks that traditionally required command-line operations.

While official use of port 311 has largely been deprecated, legacy environments may still expose this port. As the administration traffic is generally unencrypted (unless combined with VPN tunnels or layered SSL implementations), modern security practices recommend against using it, favoring updated, more secure management protocols.

Security Information

exposure of :311

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

web services averages 3.9 across 112 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

Common vulnerabilities:

  • Unencrypted traffic exposes sensitive configuration data and credentials to eavesdropping.
  • Susceptibility to brute-force attacks if weak administrative passwords are in place.
  • Potential exploitation of outdated or unpatched server software leading to unauthorized server control or service disruption.

Common mitigations:

  • Restrict access to port 311 using strict firewall rules, limiting it to trusted management IPs.
  • Employ strong, complex authentication credentials and enable account lockout policies to prevent brute-force attacks.
  • Layer port 311 access behind secure VPN tunnels to encrypt traffic.
  • Decommission or disable legacy Mac OS X Server components if not needed or migrate to supported management interfaces.
  • Regularly update server software to patch vulnerabilities and disable web-based administration if alternative management methods are available.

the 8 most looked-up other ports in web services — 112 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted