cheat sheet
Common Ports Cheat Sheet
The ports you see in firewall rules, scan results and config files, grouped by job. Defaults can be changed, so a port number is a strong hint, not proof of what is running: confirm with a service scan.
by Muhammad Usman · updated Oct 08, 2026
Port ranges
Range
Name
Notes
0-1023
Well-known (system) ports
Binding needs root / CAP_NET_BIND_SERVICE on Linux
1024-49151
Registered ports
Assigned by IANA to specific services (databases, brokers, ...)
49152-65535
Dynamic / ephemeral
Client-side source ports. Windows uses this range; Linux defaults to 32768-60999
A connection is identified by protocol + source IP + source port + destination IP + destination port, so many clients can talk to port 443 at once.
Web, proxies and remote access
Port
Proto
Service
Security notes
80
TCP
HTTP
Cleartext: redirect to 443 and send HSTS
443
TCP
HTTPS (HTTP/1.1, HTTP/2 over TLS)
The default for anything public
443
UDP
HTTP/3 (QUIC)
Firewalls that only allow TCP 443 silently push clients back to HTTP/2
8080
TCP
HTTP alternate, app servers, proxies
Often dev / admin panels left exposed
8443
TCP
HTTPS alternate, admin consoles
Same: check for exposed management UIs
8000, 5000, 3000
TCP
Dev servers (uvicorn / Django, Flask, Node / Grafana)
Should never face the internet
1080
TCP
SOCKS proxy
Open proxies get abused within hours
3128
TCP
Squid HTTP proxy
Restrict by source IP and auth
9050
TCP
Tor SOCKS proxy (9150 for Tor Browser)
Local only
22
TCP
SSH, SFTP, SCP
Keys only, no password logins; expect constant brute-force noise
23
TCP
Telnet
Cleartext, including passwords: replace with SSH
3389
TCP/UDP
RDP (Windows Remote Desktop)
Never expose directly; put it behind a VPN; brute-forced constantly
5900
TCP
VNC (5900 + display number)
Weak auth, often unencrypted: tunnel it over SSH
5985 / 5986
TCP
WinRM over HTTP / HTTPS
Remote PowerShell; internal only
Email
Port
Proto
Service
Security notes
25
TCP
SMTP (server-to-server relay)
Many ISPs and clouds block outbound 25; open relays get blacklisted
587
TCP
SMTP submission + STARTTLS
Where mail clients send with authentication
465
TCP
SMTP submission over implicit TLS
Back in favour (RFC 8314)
110 / 995
TCP
POP3 / POP3 over TLS
Use 995
143 / 993
TCP
IMAP / IMAP over TLS
Use 993
Name resolution, time and network plumbing
Port
Proto
Service
Security notes
53
UDP + TCP
DNS
TCP for large answers and zone transfers. Open resolvers are used for amplification DDoS; restrict AXFR
853
TCP (UDP for DoQ)
DNS over TLS / DNS over QUIC
Encrypted DNS (DNS over HTTPS uses 443)
5353
UDP
mDNS (Bonjour, .local)
LAN only; leaks device names
5355
UDP
LLMNR
Spoofable on LANs (credential capture with tools like Responder); disable it
67 / 68
UDP
DHCP server / client
Rogue DHCP servers can hijack a LAN: use DHCP snooping
546 / 547
UDP
DHCPv6 client / server
123
UDP
NTP
Old monlist amplification; bad time breaks TLS and Kerberos
161 / 162
UDP
SNMP / SNMP traps
v1/v2c send the community string ("public") in cleartext: use SNMPv3
514
UDP
Syslog
Cleartext and spoofable; syslog over TLS uses 6514
69
UDP
TFTP
No authentication; network boot and device configs
179
TCP
BGP
Peers only; filter and authenticate sessions
1900
UDP
SSDP / UPnP
Amplification DDoS source; never expose
4789
UDP
VXLAN
Overlay networks; unauthenticated, keep internal
File sharing and Windows / directory services
Port
Proto
Service
Security notes
20 / 21
TCP
FTP data / control
Cleartext credentials: use SFTP (22) or FTPS (989/990)
445
TCP
SMB (Windows file sharing)
Never expose to the internet (EternalBlue / WannaCry)
137, 138 / 139
UDP / TCP
NetBIOS name, datagram / session
Legacy; leaks host info; block at the edge
135
TCP
Microsoft RPC endpoint mapper
Internal only
88
TCP/UDP
Kerberos
Domain auth; Kerberoasting targets service accounts
389 / 636
TCP
LDAP / LDAP over TLS
Use 636 or StartTLS; anonymous binds leak the directory
3268 / 3269
TCP
Active Directory Global Catalog / over TLS
Internal only
2049
TCP/UDP
NFS
Restrict exports by host; weak by default
111
TCP/UDP
rpcbind / portmapper
Lists RPC services to anyone who asks
873
TCP
rsync daemon
Unauthenticated modules expose files
VPNs and tunnels
Port
Proto
Service
Notes
500 / 4500
UDP
IPsec IKE / NAT traversal
Site-to-site and many client VPNs
1194
UDP (or TCP)
OpenVPN default
51820
UDP
WireGuard (conventional default)
Silent to unauthenticated packets, so scans see nothing
1701
UDP
L2TP
Normally wrapped in IPsec
1723
TCP
PPTP (plus GRE)
Broken crypto: do not use
3478 / 5349
UDP/TCP
STUN / TURN, TURN over TLS
WebRTC NAT traversal
Databases, caches and queues
These are the services most often found wide open on the internet. Bind them to localhost or a private network, require auth, and firewall them.
Port
Proto
Service
Security notes
3306
TCP
MySQL / MariaDB
Never public; use TLS for remote clients
5432
TCP
PostgreSQL
Check pg_hba.conf: no trust for remote hosts
1433 / 1434
TCP / UDP
Microsoft SQL Server / SQL Browser
Brute-forced constantly when exposed
1521
TCP
Oracle DB listener
Internal only
27017
TCP
MongoDB
Old versions listened on all interfaces with no auth (mass ransom wipes); 3.6+ binds localhost
6379
TCP
Redis
No auth by default (protected mode since 3.2); an exposed Redis can lead to code execution
11211
TCP/UDP
Memcached
UDP amplification behind record DDoS attacks; UDP is off by default since 1.5.6
9200 / 9300
TCP
Elasticsearch HTTP / transport
Many data leaks from open clusters; enable security
5601
TCP
Kibana
Behind auth
9042
TCP
Cassandra CQL
5984
TCP
CouchDB
5672 / 5671
TCP
AMQP (RabbitMQ) / over TLS
Management UI on 15672: change the default guest login
9092
TCP
Kafka
Enable SASL / TLS
2181
TCP
ZooKeeper
No auth by default
1883 / 8883
TCP
MQTT / MQTT over TLS
IoT; anonymous brokers leak sensor data
Containers, orchestration and monitoring
Port
Proto
Service
Security notes
2375 / 2376
TCP
Docker API plain / TLS
An open 2375 is root on the host: never expose it
6443
TCP
Kubernetes API server
Authenticated; restrict by network as well
10250
TCP
kubelet API
Anonymous access lets attackers exec into pods
2379 / 2380
TCP
etcd client / peer
Holds every cluster secret: mTLS only
9090
TCP
Prometheus
Metrics leak internal hostnames and versions
9100
TCP
node_exporter (also raw printing / JetDirect)
3000
TCP
Grafana
Change the default admin login
8888
TCP
Jupyter
Token-protected by default; an open notebook is remote code execution
5060 / 5061
UDP+TCP / TCP
SIP / SIP over TLS (VoIP)
Toll fraud scanners hit it constantly
554
TCP
RTSP (IP cameras)
Default credentials expose live feeds
Check what is listening
Task
Command
Listening sockets with owning process (Linux)
sudo ss -tulpn
Who holds port 8080 (Linux / macOS)
sudo lsof -iTCP:8080 -sTCP:LISTEN
Listening ports (Windows)
netstat -ano | findstr LISTENING
Who holds port 8080 (PowerShell)
Get-NetTCPConnection -LocalPort 8080
Is a remote TCP port reachable?
nc -zv example.com 443
Same, from PowerShell
Test-NetConnection example.com -Port 443
Identify services on ports
nmap -sV -p 22,80,443 host
Scan UDP (slow, needs root)
sudo nmap -sU -p 53,123,161 host
Only scan hosts you own or have written permission to test.
import socket
def is_open(host, port, timeout=2.0):
# TCP connect check. UDP cannot be checked this way: no reply != closed.
try:
with socket.create_connection((host, port), timeout=timeout):
return True
except OSError:
return False
print(is_open("example.com", 443))
Hardening checklist
Default deny inbound; open only what a host needs, and only to the sources that need it.
Admin and database ports (22, 3389, 3306, 5432, 6379, 9200, 2375...) belong behind a VPN or bastion, not on a public IP.
Prefer the TLS variant: 993 over 143, 995 over 110, 636 over 389, 8883 over 1883, SFTP over FTP.
Moving SSH to another port cuts log noise but is not security: still use keys and rate limits.
Re-scan your own public IPs from outside regularly; cloud security groups and Docker port mappings drift.
Nothing on this sheet matches. Clear the filter