Samba's old SWAT web admin interface; Samba removed it in 4.1.0, so a live 901 today is usually something else.
SWAT was a small CGI web interface for editing smb.conf and starting/stopping Samba, run out of inetd or xinetd on port 901 and protected by HTTP Basic authentication over an unencrypted connection by default. Samba's 4.1.0 release notes list it under removed components, so no current Samba install listens here. IANA's actual registration for 901 is smpnameres, unrelated, and nmap's service table also notes ISS RealSecure using this 901–903 neighbourhood. On a modern scan, 901 is an unidentified service until you look at what it answers.
Do not expose
SWAT accepted the root password over cleartext HTTP and could rewrite smb.conf on submission — if you have found a real one, it is a remote root path, and an unidentified listener here deserves the same suspicion.
$ curl -sI --max-time 5 http://TARGET:901/Seen this on your network? Beige Box scans your Wi-Fi and shows every open port on every device — and its Ports tool links straight back here.
Get Beige Box →also available as JSON · Markdown
Corrections or a missing port? Reply @rimrocksystems.