Port 90DNSIX
**DNSIX** (DoD Network Security for Information Exchange) facilitates secure attribute-based access control within Department of Defense networks, enabling attribute token mapping to govern data exchange securely across interconnected systems..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 2/10
- lookups
- 16,082
2 transports registered
payload readable on path
registered with iana
safe
rank 185 of 993 · top 19%
1 other service is registered on port 90. compare all 2 →
Technical Details
what runs on :90DNSIX, short for DoD Network Security for Information Exchange, is a protocol and framework engineered to enable secure communication within Department of Defense networks. It primarily focuses on embedding security attributes within data packets via token mapping. This mapping approach allows systems interconnected within DoD environments to enforce strict access controls and data labeling according to classification or user privilege level.
Technically, DNSIX operates by generating and embedding security attribute tokens within transmitted data. These tokens encapsulate metadata like classification level, user role, or origin, which downstream systems can read and act upon to grant, restrict, or log access. By doing so, the protocol facilitates granular and attribute-driven security policies that are critical in multi-domain, multi-level security environments such as those in defense sectors.
Its implementation typically involves both TCP and UDP transports, ensuring flexible communication channels. While less prominent in contemporary commercial deployments, DNSIX remains relevant in specialized, legacy, or highly regulated government infrastructures that demand robust attribute tagging for information control.
Security Information
exposure of :90risk score
2/ 10safe
routine exposure. this port is rarely the way in on its own — keep it patched and logged and move on.
security averages 3.8 across 216 ports — this one sits 1.8 below.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common vulnerabilities:
- Improper validation or parsing of security attribute tokens, allowing privilege escalation or bypass attacks.
- Lack of strong authentication between communicating entities, potentially exposing sensitive security labels to interception or spoofing.
- Use of outdated or weak token encryption (or plain-text tokens), leading to token harvesting or metadata leakage.
Common mitigations:
- Implement strict token validation routines to detect malformed or unauthorized tokens.
- Employ mutual authentication and integrity mechanisms such as cryptographic signatures to prevent spoofing or tampering.
- Where feasible, upgrade transport layers to utilize encrypted channels (e.g., VPNs, encrypted tunnels), limiting metadata exposure.
- Regularly audit token mapping policies and access control logic to ensure compliance and reduce attack surface.
Related Ports
the 8 most looked-up other ports in security — 216 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :443 | HTTPS | TCPtls | Web Services | caution | 65.9k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Squid Proxy HTTP | TCP | Web Services | caution | 45.8k |
| :8080 | HTTP Alternate | TCPtls | Web Services | caution | 44.9k |
| :7000 | Vuze HTTPS Tracker | TCPtls | Security | caution | 28.9k |
risk mix of the 8 listed
- caution100%
3 of 8 encrypted