Port 560Remote Monitor (rmonitor)

Remote Monitor (rmonitor) is a UDP-based protocol primarily utilized for monitoring networked systems and services remotely. It enables administrators to collect real-time data regarding the health and performance of various hosts, facilitating proactive operations management and rapid troubleshooting..

transport
udp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
5/10

caution

lookups
6,101

rank 816 of 993 · top 82%

Technical Details

what runs on :560

Remote Monitor (rmonitor) operating over UDP port 560 is designed to facilitate lightweight, real-time monitoring of remote systems. Its reliance on UDP allows for fast transmission of status queries and responses without the overhead of connection management, making it suitable for network environments where quick updates are critical.

Typically, rmonitor can gather a variety of metrics such as system load, uptime, availability of services, and potentially some application-specific data if configured accordingly. It operates using a request-response pattern, where a monitoring client periodically queries one or multiple remote hosts, which then respond with their current status data.

While specialized monitoring protocols such as SNMP have become more common, legacy systems or custom-built environments might still employ rmonitor due to its simplicity and minimal resource requirements. Modern monitoring stacks may integrate or replace it depending on compatibility and feature sets desired.

Security Information

exposure of :560

risk score

5/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 1.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common vulnerabilities:

  • Since rmonitor traffic is unencrypted by design, sensitive operational information can be intercepted by attackers performing network sniffing.
  • The lack of authentication mechanisms in default implementations may allow unauthorized access to monitoring data or permit spoofing attacks, where false information is sent to the client.
  • UDP-based services are inherently more susceptible to amplification or reflection DDoS attacks.

Common mitigations:

  • Segmenting monitoring communication to dedicated management VLANs or isolated network segments to reduce exposure.
  • Implementing strict ACLs (Access Control Lists) or network firewall rules to restrict access only to trusted monitoring clients.
  • If possible, encapsulating monitoring traffic within VPN tunnels or applying network encryption solutions to secure data in transit.
  • Monitoring for abnormal traffic patterns indicative of scanning or exploitation attempts targeting port 560.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted