Port 7004AFS/Kerberos Authentication Service

Legacy AFS authentication service using Kerberos to authenticate users and issue AFS credentials.

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
6/10

risk

lookups
0

rank 994 of 1,818 · top 55%

also known as afs3-kaserver, AFS kaserver, AFS authentication server

Technical Details

what runs on :7004

The kaserver provides the AFS authentication service using the AFS Kerberos-based protocol, normally over UDP and also supporting TCP. It is part of the traditional AFS service-port group, alongside services such as the protection server on 7002 and the volume location server on 7003. Authentication exchanges use Kerberos cryptographic protection for tickets and password-derived data, but the transport itself is not a general-purpose encrypted channel.

Security Information

exposure of :7004

risk score

6/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

security averages 3.7 across 237 ports — this one sits 2.3 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

This is a sensitive legacy authentication endpoint and should not be exposed directly to the public Internet. An exposed service can be subject to principal enumeration, password-guessing, denial-of-service, and attacks against old AFS or Kerberos implementations; restrict it to trusted AFS clients and replace kaserver with a maintained Kerberos-based design where possible.

the 8 most looked-up other ports in security — 237 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted