Port 560Remote Monitor (rmonitor)
Remote Monitor (rmonitor) is a UDP-based protocol primarily utilized for monitoring networked systems and services remotely. It enables administrators to collect real-time data regarding the health and performance of various hosts, facilitating proactive operations management and rapid troubleshooting..
- transport
- udp
- in transit
- cleartext
- assignment
- official
- risk
- 5/10
- lookups
- 6,101
single transport
payload readable on path
registered with iana
caution
rank 816 of 993 · top 82%
Technical Details
what runs on :560Remote Monitor (rmonitor) operating over UDP port 560 is designed to facilitate lightweight, real-time monitoring of remote systems. Its reliance on UDP allows for fast transmission of status queries and responses without the overhead of connection management, making it suitable for network environments where quick updates are critical.
Typically, rmonitor can gather a variety of metrics such as system load, uptime, availability of services, and potentially some application-specific data if configured accordingly. It operates using a request-response pattern, where a monitoring client periodically queries one or multiple remote hosts, which then respond with their current status data.
While specialized monitoring protocols such as SNMP have become more common, legacy systems or custom-built environments might still employ rmonitor due to its simplicity and minimal resource requirements. Modern monitoring stacks may integrate or replace it depending on compatibility and feature sets desired.
Security Information
exposure of :560risk score
5/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 1.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common vulnerabilities:
- Since rmonitor traffic is unencrypted by design, sensitive operational information can be intercepted by attackers performing network sniffing.
- The lack of authentication mechanisms in default implementations may allow unauthorized access to monitoring data or permit spoofing attacks, where false information is sent to the client.
- UDP-based services are inherently more susceptible to amplification or reflection DDoS attacks.
Common mitigations:
- Segmenting monitoring communication to dedicated management VLANs or isolated network segments to reduce exposure.
- Implementing strict ACLs (Access Control Lists) or network firewall rules to restrict access only to trusted monitoring clients.
- If possible, encapsulating monitoring traffic within VPN tunnels or applying network encryption solutions to secure data in transit.
- Monitoring for abnormal traffic patterns indicative of scanning or exploitation attempts targeting port 560.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted