Port 5500Hotline / VNC reverse-connection listener

Historically used by Hotline servers and by VNC viewers awaiting reverse RFB connections; neither use is implied by the IANA assignment.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
6/10

risk

lookups
0

rank 993 of 5,503 · top 18%

also known as fcp-addr-srvr1, VNC reverse connection, RFB

1 other service is registered on port 5500. compare all 2 →

Technical Details

what runs on :5500

The registered service name is fcp-addr-srvr1, but the best-known uses of TCP 5500 are unrelated. Hotline clients traditionally connect to servers on TCP 5500 using Hotline's proprietary protocol. VNC viewers in listen mode commonly accept server-initiated callbacks on TCP 5500; the RFB connection begins with a version exchange followed by security-type negotiation. Ordinary VNC connections instead typically use TCP 5900 plus the display number. The registry also lists UDP, but these common Hotline and VNC uses are TCP-based; an open UDP port cannot be identified from the assignment alone.

Security Information

exposure of :5500

risk score

6/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

file transfer averages 3.4 across 186 ports — this one sits 2.6 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Do not expose an unexpected listener without identifying it. A VNC callback listener can lead to desktop access depending on the negotiated security and viewer configuration; RFB does not encrypt the desktop stream by default, and some configurations permit no authentication. Hotline is a legacy service, so its access controls and any encryption depend on the implementation. Restrict access to trusted networks and use a secure tunnel where needed.

the 8 most looked-up other ports in file transfer — 186 ports carry that label.

risk mix of the 8 listed

  • caution100%

1 of 8 encrypted