Port 504Citadel Groupware
Port 504 is primarily used by Citadel groupware, a collaborative client-server platform offering email, calendar, contacts, bulletin boards, and more. This port facilitates dedicated Citadel protocol communications between specialized clients and the Citadel server, enabling multiservice access within the unified groupware environment. Both TCP and UDP are supported for flexible and reliable data transfer, underpinning internal messaging, directory access, and real-time collaboration functions..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 5,011
2 transports registered
payload readable on path
registered with iana
caution
rank 920 of 993 · top 93%
Technical Details
what runs on :504Citadel is an open-source, multi-user collaboration server providing integrated functionalities such as email, calendars, address books, bulletin boards, instant messaging, and more. The system supports multiple access protocols (IMAP, POP3, SMTP, XMPP), but port 504 is specifically designated for its native Citadel protocol, mainly used by specialized Citadel clients.
Communications over port 504 facilitate seamless synchronization of groupware data, enabling clients to perform real-time updates, retrieve messages, manage calendars, or access conferencing features. The protocol is designed to efficiently multiplex different groupware services over a single dedicated channel, optimizing internal client-server interactions.
Both TCP and UDP are supported: TCP ensures reliable, connection-oriented data delivery for complex operations, while UDP can be used for lightweight or real-time status updates within the Citadel system. However, communications on this port are typically unencrypted by default, necessitating additional measures if confidentiality is required.
Security Information
exposure of :504risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
web services averages 3.9 across 112 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common Vulnerabilities:
- Lack of encryption exposes authentication credentials and sensitive data to interception (Man-in-the-middle attacks).
- Improper access controls can facilitate unauthorized data retrieval or abuse of collaborative functions.
- Potential for service-specific exploitation such as buffer overflows or protocol misuse.
- Susceptibility to common denial-of-service (DoS) attacks targeting UDP or TCP services on this port.
Common Mitigations:
- Restrict access to port 504 via firewall rules to trusted client IPs only.
- Enable secure tunneling methods (e.g., SSL/TLS wrapping, VPNs) to protect data in transit.
- Employ robust authentication and authorization policies within Citadel.
- Regularly update Citadel server software to patch known vulnerabilities.
- Monitor network traffic on this port for suspicious activity or abuse patterns.
- Disable UDP if not explicitly needed to reduce attack surface.
Related Ports
the 8 most looked-up other ports in web services — 112 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8888 | Sun Answerbook & Alt HTTP | TCP | Web Services | caution | 123.9k |
| :8000 | Intel Remote Desktop / Alternate HTTP Port | TCP | Web Services | safe | 84.3k |
| :8888 | NewsEDGE | TCPUDP | Web Services | caution | 83.3k |
| :8888 | HTTP Alternative Port | TCP | Web Services | caution | 76.5k |
| :8888 | GNUmp3d Streaming HTTP | TCP | Web Services | caution | 76.3k |
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :80 | HTTP | TCPUDP | Web Services | caution | 67.3k |
risk mix of the 8 listed
- safe13%
- caution88%
0 of 8 encrypted