Port 760Kerberos Registration

Port 760 is utilized by the Kerberos registration service (known as krbupdate or kreg). It facilitates the registration and update of Kerberos principals and credentials, enabling centralized identity management and secure authentication within a networked environment..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
2/10

safe

lookups
5,951

rank 833 of 993 · top 84%

1 other service is registered on port 760. compare all 2

Technical Details

what runs on :760

Port 760 serves the Kerberos registration daemon (krbupdate/kreg), an auxiliary component of Kerberos environments. This service allows users and administrators to register new principals, modify credentials, or update key tables securely. It bridges the gap between identity provisioning and secure authentication processes that Kerberos is known for.

Typically, the krbupdate service operates over both TCP and UDP, providing flexibility depending on network requirements. TCP ensures reliable delivery of update requests and confirmations, while UDP can reduce latency for simpler or more lightweight transactions. The port is generally open internally within trusted segments of enterprise or academic networks, often during initial setup phases or periodic credential rotations.

Unlike ports 88 or 464, which handle authentication queries or password changes, port 760's role is provisioning credentials. The krbupdate service integrates closely with the Key Distribution Center (KDC) to maintain accurate and secure identity records, publishing new keys without exposing sensitive data to the network unlawfully.

Security Information

exposure of :760

risk score

2/ 10safe

routine exposure. this port is rarely the way in on its own — keep it patched and logged and move on.

security averages 3.8 across 216 ports — this one sits 1.8 below.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Unauthorized access to the registration service leading to fraudulent principal creation
  • Interception or spoofing of unencrypted traffic, allowing attackers to capture sensitive identity data
  • Exploitation of outdated krbupdate implementations with unpatched flaws

Mitigations:

  • Restrict access to port 760 using firewalls and network segmentation, allowing only trusted management hosts
  • Enable encryption (such as via Kerberos session encryption or protective tunnels like IPsec)
  • Employ strict authentication and authorization controls when registering or updating principals
  • Monitor and audit registration activities for suspicious behavior
  • Keep Kerberos infrastructure, including registration daemons, updated with the latest security patches

the 8 most looked-up other ports in security — 216 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted