Port 9080Groove RPC
GLRPC stands for Groove Lightweight Remote Procedure Call, a proprietary protocol used by the Groove Collaboration software suite, which was later integrated into Microsoft SharePoint Workspace before its discontinuation. It facilitated real-time communication, synchronization, and data sharing within Groove's peer-to-peer workspace environment..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 70,783
2 transports registered
payload readable on path
registered with iana
caution
rank 8 of 993 · top 1%
1 other service is registered on port 9080. compare all 2 →
Technical Details
what runs on :9080-
Groove Collaboration Software was acquired by Microsoft in 2005 from Groove Networks and aimed to provide a secure peer-to-peer collaboration environment, enabling teams to work together on documents and projects without needing centralized storage.
-
GLRPC (Groove Lightweight RPC) operated on port 9080 to facilitate communication between Groove clients. It handled messaging, file synchronization, and workspace management by exchanging remote procedure call (RPC) messages over TCP and UDP.
-
Following its acquisition, Microsoft integrated Groove into SharePoint Workspace, extending collaboration capabilities primarily for offline SharePoint access. Despite its eventual discontinuation, understanding GLRPC's protocol behavior is important for legacy network configurations and security audits.
Security Information
exposure of :9080risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
web services averages 3.9 across 112 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
-
Common Vulnerabilities:
- Since Groove was discontinued, its network components may be outdated and unpatched, increasing susceptibility to attacks.
- The peer-to-peer nature and lack of encryption by default can expose sensitive data to interception via man-in-the-middle attacks.
- Exposed port 9080 may be exploited by attackers for reconnaissance or unauthorized access, especially if unused legacy clients linger.
-
Common Mitigations:
- Disable or block traffic on port 9080 if Groove or SharePoint Workspace functionalities are no longer used.
- Use network segmentation and firewall rules to restrict access only to trusted hosts.
- Monitor for unexpected activity on this port indicative of legacy or unauthorized software operation.
- Consider full decommissioning and system upgrade paths to eliminate reliance on deprecated protocols.
Related Ports
the 8 most looked-up other ports in web services — 112 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8888 | Sun Answerbook & Alt HTTP | TCP | Web Services | caution | 123.9k |
| :8000 | Intel Remote Desktop / Alternate HTTP Port | TCP | Web Services | safe | 84.3k |
| :8888 | NewsEDGE | TCPUDP | Web Services | caution | 83.3k |
| :8888 | HTTP Alternative Port | TCP | Web Services | caution | 76.5k |
| :8888 | GNUmp3d Streaming HTTP | TCP | Web Services | caution | 76.3k |
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :80 | HTTP | TCPUDP | Web Services | caution | 67.3k |
| :8882 | Atlasz Secure App Server | TCP | Web Services | caution | 66.9k |
risk mix of the 8 listed
- safe13%
- caution88%
0 of 8 encrypted