Port 387AURP
AppleTalk Update-based Routing Protocol (AURP) facilitates routing updates within AppleTalk internetworks, allowing geographically dispersed Apple networks to exchange routing information efficiently. It was primarily used to enable communication over wide area networks by encapsulating AppleTalk packets within IP, supporting AppleTalk's expansion beyond local segments..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 8,324
2 transports registered
payload readable on path
registered with iana
caution
rank 599 of 993 · top 60%
Technical Details
what runs on :387-
AppleTalk Update-based Routing Protocol (AURP) was developed by Apple to extend AppleTalk networking capabilities over IP-based wide area networks (WANs).
-
It works by encapsulating AppleTalk data packets inside IP packets, effectively tunneling AppleTalk traffic across IP networks, thereby enabling the connection of distant AppleTalk networks without relying exclusively on native AppleTalk WAN links.
-
AURP routers, known as tunnel endpoints, maintain AppleTalk routing tables and exchange routing update packets via UDP or TCP on port 387. This supports dynamic routing updates, helping maintain up-to-date path information between AppleTalk subnets and ensuring consistency across the internetwork.
Security Information
exposure of :387risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
-
Common Vulnerabilities:
- Since AURP transmits routing information openly without encryption, it is susceptible to packet interception, spoofing, and man-in-the-middle attacks.
- Attackers might inject false routing updates, leading to network misrouting, segmentation, or denial of service.
- Exposing this port publicly can increase risks in mixed network environments, enabling exploits from legacy AppleTalk protocol weaknesses.
-
Common Mitigations:
- Filter and restrict port 387 traffic at network boundaries to allow only trusted routing peers.
- Segment legacy AppleTalk systems from critical production networks with firewalls or VLANs.
- Disable or remove AURP capabilities on unused systems.
- Consider network modernization efforts to phase out AppleTalk and dependent services to reduce attack surface.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted