Port Authority Edition – Internet Vulnerability Profiling
by Steve Gibson,  Gibson Research Corporation.

Probe Port 111
Port 111


SUN Remote Procedure Call

This port is used as a well-defined means for determining the ports upon which other services in the system are running. It is referred to as a "portmapper" because it provides a directory, or "mapping" between available services and their ports. This is similar to Microsoft's infamous DCOM DCE port 135.

Port 111 is a security vulnerability for UNIX systems due to the number of vulnerabilities discovered for the portmapper and related RPC services.

The SANS Institute provides a general introduction to the security vulnerabilities associated with port 111.

Remote Procedure Call (RPC) details (the complete specifications)





