Port 9080Groove RPC

GLRPC stands for Groove Lightweight Remote Procedure Call, a proprietary protocol used by the Groove Collaboration software suite, which was later integrated into Microsoft SharePoint Workspace before its discontinuation. It facilitated real-time communication, synchronization, and data sharing within Groove's peer-to-peer workspace environment..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
70,783

rank 8 of 993 · top 1%

1 other service is registered on port 9080. compare all 2

Technical Details

what runs on :9080
  • Groove Collaboration Software was acquired by Microsoft in 2005 from Groove Networks and aimed to provide a secure peer-to-peer collaboration environment, enabling teams to work together on documents and projects without needing centralized storage.

  • GLRPC (Groove Lightweight RPC) operated on port 9080 to facilitate communication between Groove clients. It handled messaging, file synchronization, and workspace management by exchanging remote procedure call (RPC) messages over TCP and UDP.

  • Following its acquisition, Microsoft integrated Groove into SharePoint Workspace, extending collaboration capabilities primarily for offline SharePoint access. Despite its eventual discontinuation, understanding GLRPC's protocol behavior is important for legacy network configurations and security audits.

Security Information

exposure of :9080

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

web services averages 3.9 across 112 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

  • Common Vulnerabilities:

    • Since Groove was discontinued, its network components may be outdated and unpatched, increasing susceptibility to attacks.
    • The peer-to-peer nature and lack of encryption by default can expose sensitive data to interception via man-in-the-middle attacks.
    • Exposed port 9080 may be exploited by attackers for reconnaissance or unauthorized access, especially if unused legacy clients linger.
  • Common Mitigations:

    • Disable or block traffic on port 9080 if Groove or SharePoint Workspace functionalities are no longer used.
    • Use network segmentation and firewall rules to restrict access only to trusted hosts.
    • Monitor for unexpected activity on this port indicative of legacy or unauthorized software operation.
    • Consider full decommissioning and system upgrade paths to eliminate reliance on deprecated protocols.

the 8 most looked-up other ports in web services — 112 ports carry that label.

risk mix of the 8 listed

  • safe13%
  • caution88%

0 of 8 encrypted