Port ranges

Range Name Notes
0-1023 Well-known (system) ports Binding needs root / CAP_NET_BIND_SERVICE on Linux
1024-49151 Registered ports Assigned by IANA to specific services (databases, brokers, ...)
49152-65535 Dynamic / ephemeral Client-side source ports. Windows uses this range; Linux defaults to 32768-60999

A connection is identified by protocol + source IP + source port + destination IP + destination port, so many clients can talk to port 443 at once.

Web, proxies and remote access

Port Proto Service Security notes
80 TCP HTTP Cleartext: redirect to 443 and send HSTS
443 TCP HTTPS (HTTP/1.1, HTTP/2 over TLS) The default for anything public
443 UDP HTTP/3 (QUIC) Firewalls that only allow TCP 443 silently push clients back to HTTP/2
8080 TCP HTTP alternate, app servers, proxies Often dev / admin panels left exposed
8443 TCP HTTPS alternate, admin consoles Same: check for exposed management UIs
8000, 5000, 3000 TCP Dev servers (uvicorn / Django, Flask, Node / Grafana) Should never face the internet
1080 TCP SOCKS proxy Open proxies get abused within hours
3128 TCP Squid HTTP proxy Restrict by source IP and auth
9050 TCP Tor SOCKS proxy (9150 for Tor Browser) Local only
22 TCP SSH, SFTP, SCP Keys only, no password logins; expect constant brute-force noise
23 TCP Telnet Cleartext, including passwords: replace with SSH
3389 TCP/UDP RDP (Windows Remote Desktop) Never expose directly; put it behind a VPN; brute-forced constantly
5900 TCP VNC (5900 + display number) Weak auth, often unencrypted: tunnel it over SSH
5985 / 5986 TCP WinRM over HTTP / HTTPS Remote PowerShell; internal only

Email

Port Proto Service Security notes
25 TCP SMTP (server-to-server relay) Many ISPs and clouds block outbound 25; open relays get blacklisted
587 TCP SMTP submission + STARTTLS Where mail clients send with authentication
465 TCP SMTP submission over implicit TLS Back in favour (RFC 8314)
110 / 995 TCP POP3 / POP3 over TLS Use 995
143 / 993 TCP IMAP / IMAP over TLS Use 993

Name resolution, time and network plumbing

Port Proto Service Security notes
53 UDP + TCP DNS TCP for large answers and zone transfers. Open resolvers are used for amplification DDoS; restrict AXFR
853 TCP (UDP for DoQ) DNS over TLS / DNS over QUIC Encrypted DNS (DNS over HTTPS uses 443)
5353 UDP mDNS (Bonjour, .local) LAN only; leaks device names
5355 UDP LLMNR Spoofable on LANs (credential capture with tools like Responder); disable it
67 / 68 UDP DHCP server / client Rogue DHCP servers can hijack a LAN: use DHCP snooping
546 / 547 UDP DHCPv6 client / server
123 UDP NTP Old monlist amplification; bad time breaks TLS and Kerberos
161 / 162 UDP SNMP / SNMP traps v1/v2c send the community string ("public") in cleartext: use SNMPv3
514 UDP Syslog Cleartext and spoofable; syslog over TLS uses 6514
69 UDP TFTP No authentication; network boot and device configs
179 TCP BGP Peers only; filter and authenticate sessions
1900 UDP SSDP / UPnP Amplification DDoS source; never expose
4789 UDP VXLAN Overlay networks; unauthenticated, keep internal

File sharing and Windows / directory services

Port Proto Service Security notes
20 / 21 TCP FTP data / control Cleartext credentials: use SFTP (22) or FTPS (989/990)
445 TCP SMB (Windows file sharing) Never expose to the internet (EternalBlue / WannaCry)
137, 138 / 139 UDP / TCP NetBIOS name, datagram / session Legacy; leaks host info; block at the edge
135 TCP Microsoft RPC endpoint mapper Internal only
88 TCP/UDP Kerberos Domain auth; Kerberoasting targets service accounts
389 / 636 TCP LDAP / LDAP over TLS Use 636 or StartTLS; anonymous binds leak the directory
3268 / 3269 TCP Active Directory Global Catalog / over TLS Internal only
2049 TCP/UDP NFS Restrict exports by host; weak by default
111 TCP/UDP rpcbind / portmapper Lists RPC services to anyone who asks
873 TCP rsync daemon Unauthenticated modules expose files

VPNs and tunnels

Port Proto Service Notes
500 / 4500 UDP IPsec IKE / NAT traversal Site-to-site and many client VPNs
1194 UDP (or TCP) OpenVPN default
51820 UDP WireGuard (conventional default) Silent to unauthenticated packets, so scans see nothing
1701 UDP L2TP Normally wrapped in IPsec
1723 TCP PPTP (plus GRE) Broken crypto: do not use
3478 / 5349 UDP/TCP STUN / TURN, TURN over TLS WebRTC NAT traversal

Databases, caches and queues

These are the services most often found wide open on the internet. Bind them to localhost or a private network, require auth, and firewall them.

Port Proto Service Security notes
3306 TCP MySQL / MariaDB Never public; use TLS for remote clients
5432 TCP PostgreSQL Check pg_hba.conf: no trust for remote hosts
1433 / 1434 TCP / UDP Microsoft SQL Server / SQL Browser Brute-forced constantly when exposed
1521 TCP Oracle DB listener Internal only
27017 TCP MongoDB Old versions listened on all interfaces with no auth (mass ransom wipes); 3.6+ binds localhost
6379 TCP Redis No auth by default (protected mode since 3.2); an exposed Redis can lead to code execution
11211 TCP/UDP Memcached UDP amplification behind record DDoS attacks; UDP is off by default since 1.5.6
9200 / 9300 TCP Elasticsearch HTTP / transport Many data leaks from open clusters; enable security
5601 TCP Kibana Behind auth
9042 TCP Cassandra CQL
5984 TCP CouchDB
5672 / 5671 TCP AMQP (RabbitMQ) / over TLS Management UI on 15672: change the default guest login
9092 TCP Kafka Enable SASL / TLS
2181 TCP ZooKeeper No auth by default
1883 / 8883 TCP MQTT / MQTT over TLS IoT; anonymous brokers leak sensor data

Containers, orchestration and monitoring

Port Proto Service Security notes
2375 / 2376 TCP Docker API plain / TLS An open 2375 is root on the host: never expose it
6443 TCP Kubernetes API server Authenticated; restrict by network as well
10250 TCP kubelet API Anonymous access lets attackers exec into pods
2379 / 2380 TCP etcd client / peer Holds every cluster secret: mTLS only
9090 TCP Prometheus Metrics leak internal hostnames and versions
9100 TCP node_exporter (also raw printing / JetDirect)
3000 TCP Grafana Change the default admin login
8888 TCP Jupyter Token-protected by default; an open notebook is remote code execution
5060 / 5061 UDP+TCP / TCP SIP / SIP over TLS (VoIP) Toll fraud scanners hit it constantly
554 TCP RTSP (IP cameras) Default credentials expose live feeds

Check what is listening

Task Command
Listening sockets with owning process (Linux) sudo ss -tulpn
Who holds port 8080 (Linux / macOS) sudo lsof -iTCP:8080 -sTCP:LISTEN
Listening ports (Windows) netstat -ano | findstr LISTENING
Who holds port 8080 (PowerShell) Get-NetTCPConnection -LocalPort 8080
Is a remote TCP port reachable? nc -zv example.com 443
Same, from PowerShell Test-NetConnection example.com -Port 443
Identify services on ports nmap -sV -p 22,80,443 host
Scan UDP (slow, needs root) sudo nmap -sU -p 53,123,161 host

Only scan hosts you own or have written permission to test.

import socket

def is_open(host, port, timeout=2.0):
    # TCP connect check. UDP cannot be checked this way: no reply != closed.
    try:
        with socket.create_connection((host, port), timeout=timeout):
            return True
    except OSError:
        return False

print(is_open("example.com", 443))

Hardening checklist

  • Default deny inbound; open only what a host needs, and only to the sources that need it.
  • Admin and database ports (22, 3389, 3306, 5432, 6379, 9200, 2375...) belong behind a VPN or bastion, not on a public IP.
  • Prefer the TLS variant: 993 over 143, 995 over 110, 636 over 389, 8883 over 1883, SFTP over FTP.
  • Moving SSH to another port cuts log noise but is not security: still use keys and rate limits.
  • Re-scan your own public IPs from outside regularly; cloud security groups and Docker port mappings drift.