Port 550new-rwho / new-who

The 'new-rwho' and 'new-who' services traditionally operate over UDP port 550, providing user information within networked UNIX systems. These protocols enable administrators to monitor logged-in users across multiple hosts, facilitating easier system management and visibility. While their use has diminished in modern secure environments, understanding these legacy protocols remains important for maintaining backward compatibility and auditing historical systems..

transport
udp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
10,070

rank 460 of 993 · top 46%

Technical Details

what runs on :550

UDP port 550 has historically been designated for the 'new-rwho' and 'new-who' services, which are successors to the original 'rwho' protocol. These services allow the broadcasting and collection of user login status information across networked UNIX systems, enabling administrators to track active sessions remotely. The protocol generally works by periodically sending updates to listening hosts, which compile these records into accessible lists of who is logged on where.

In operation, 'new-rwho' provides more efficient data handling and reduced network usage compared to its predecessor, with optimized broadcast mechanisms. It typically employs simple UDP datagrams to convey status data without any encryption or complex negotiation, prioritizing low overhead and simplicity. This design fits the trusted internal network model of its era, assuming minimal threat from internal actors.

While not widely used today due to privacy concerns and alternate, more secure user management tools, some legacy systems or controlled lab environments may still deploy 'new-rwho' and 'new-who'. Their lightweight nature and ease of setup mean occasional usage persists primarily for educational or compatibility reasons rather than mainstream administration tasks.

Security Information

exposure of :550

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Data transmitted via 'new-rwho' is unencrypted, potentially exposing user activity details to interception.
  • It can inadvertently leak sensitive internal user information to unauthorized listeners if broadcast domains are not well segregated.
  • Attackers could spoof status messages, leading to inaccurate visibility or aiding social engineering.

Common Mitigations:

  • Restrict UDP port 550 to trusted internal networks using firewalls and proper ACLs.
  • Disable or replace 'new-rwho' functionality with more secure protocols such as SSH and centralized authentication.
  • Monitor for unexpected outgoing or incoming traffic on port 550, which could indicate unintended exposure or misuse.
  • Educate users and admins on decommissioning legacy protocols to maintain privacy and reduce attack surface.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted