Loading Well-Known Ports Reference…
also called well-known
Assigned only through IETF review or IESG approval, and on Unix a process needs privilege to bind one.
also called registered
Assigned by IANA on request from anybody. An assignment here is a reservation, not an enforcement.
also called private or ephemeral
Never assigned to anything. The kernel allocates from this range for the client end of a connection.
A number matches by prefix, so 44 lists 443 and 445. Text matches the service name, the registry description and the RFC it cites.
System, user and dynamic ports together.
echoEchochargenCharacter GeneratorExposure Left open, chargen is an amplification source for reflected floods; there is no reason to run it today.
ftp-dataFile Transfer [Default Data]ftp-dataFTPftpFile Transfer Protocol [Control]ftpFTPExposure Control channel and credentials are plaintext. Use SFTP or FTPS instead of exposing it.
sshThe Secure Shell (SSH) ProtocolsshSSHIn practice Also the transport for SFTP and scp, which are SSH subsystems rather than protocols of their own.
Exposure Safe to expose, but it will be brute-forced constantly; keys rather than passwords.
telnetTelnetExposure Everything including the password crosses the wire in the clear. Nothing should answer here.
smtpSimple Mail TransferIn practice Server-to-server mail relay. Client submission belongs on 587, and many networks block outbound 25 entirely.
timeTimenicnameWho IstacacsLogin Host Protocol (TACACS)domainDomain Name ServerIn practice UDP for ordinary queries, TCP for zone transfers and any answer too large for a datagram.
Exposure An open recursive resolver is an amplification weapon. Authoritative-only, or restricted to your own clients.
bootpsBootstrap Protocol ServerbootpcBootstrap Protocol ClienttftpTrivial File TransferExposure No authentication of any kind by design. Boot networks only, never routed.
fingerFingerExposure Finger hands out account names to anyone who asks.
httpWorld Wide Web HTTPwwwWorld Wide Web HTTPwww-httpWorld Wide Web HTTPhttpHTTPIn practice Three service names are registered on this one port; http is the one anybody uses.
Exposure Fine to expose, but serve a redirect to 443 rather than content.
kerberosKerberosiso-tsapISO-TSAP Class 0In practice Carries S7 traffic to Siemens PLCs, which is why it turns up in industrial network scans.
Exposure Industrial control traffic with no authentication worth the name. Never internet-facing.
pop3Post Office Protocol - Version 3Exposure Plaintext POP3. Prefer 995, or 110 with STARTTLS enforced.
sunrpcSUN Remote Procedure CallExposure rpcbind tells a caller which ports the RPC services are on, and is an amplification source.
nntpNetwork News Transfer ProtocolntpNetwork Time ProtocolExposure An NTP server answering monlist to the internet is one of the largest amplification factors known.
epmapDCE endpoint resolutionExposure The Windows RPC endpoint mapper. Blocked at every perimeter for twenty years and still probed hourly.
netbios-nsNETBIOS Name ServiceExposure NetBIOS name service leaks host and user names to anyone who asks.
netbios-dgmNETBIOS Datagram Servicenetbios-ssnNETBIOS Session ServiceExposure SMB over NetBIOS. Along with 445, the pair that ransomware crews scan for first.
imapInternet Message Access Protocol(no service name)ReservedIn practice The udp half of this port is Reserved rather than assigned, which is true of most modern mail ports.
snmpSNMPExposure SNMP v1 and v2c authenticate with a community string in plaintext, and public is still the default.
snmptrapSNMPTRAPbgpBorder Gateway ProtocolbgpBGPExposure BGP sessions belong between known peers with authentication, never open to the internet.
ircInternet Relay Chat ProtocolldapLightweight Directory Access ProtocolExposure Plaintext LDAP carries bind credentials in the clear; use 636 or StartTLS.
svrlocServer Locationhttpshttp protocol over TLS/SSLhttpsHTTPSmicrosoft-dsMicrosoft-DSIn practice SMB direct over TCP, without the NetBIOS session layer of 139.
Exposure The single most attacked port on the internet. It has no business leaving your network.
urdURL Rendezvous Directory for SSMsubmissionsMessage Submission over TLS protocoligmpv3liteIGMP over UDP for SSMIn practice Three assignments share this number. RFC 8314 restored it for implicit-TLS mail submission after years of it being called deprecated.
isakmpisakmpmbapModbus Application ProtocolIn practice Modbus/TCP, the protocol most industrial gear speaks.
Exposure Modbus has no authentication at all; a write is a write. Air-gapped or firewalled, never exposed.
shellcmd like exec, but automatic authentication is performed as for login serversyslogNo description in the registry.In practice Two different services: shell on tcp and syslog on udp. The syslog one is what people mean.
Exposure Plaintext syslog over UDP can be forged by anyone who can reach the collector.
printerspoolerefsextended file name serverrouterlocal routing process (on site); uses variant of Xerox NS routing information protocol - RIPripngripngdhcpv6-clientDHCPv6 Clientdhcpv6-serverDHCPv6 ServerafpovertcpAFP over TCPrtspReal Time Streaming Protocol (RTSP)submissionMessage SubmissionIn practice The submission port: authenticated mail from a client, with STARTTLS.
http-rpc-epmapHTTP RPC Ep MapExposure RPC over HTTP is a route into the same Windows RPC surface as 135.
oob-ws-httpDMTF out-of-band web services management protocolasf-rmcpASF Remote Management and Control ProtocolIn practice IPMI and BMC out-of-band management. Two different assignments on tcp and udp.
Exposure A BMC is a computer inside your computer with its own weak password. Management network only.
ippIPP (Internet Printing Protocol)ippsInternet Printing Protocol over HTTPSldapsldap protocol over TLS/SSL (was sldap)ldpLDPrsyncrsyncExposure An rsync daemon with no auth module set is an anonymous read of whatever it exports.
ftps-dataftp protocol, data, over TLS/SSLftpsftp protocol, control, over TLS/SSLimapsIMAP over TLS protocol(no service name)Reservedpop3sPOP3 over TLS protocolpop3spop3 protocol over TLS/SSL (was spop3)socksSocksExposure An open SOCKS proxy will be found and used to launder somebody else’s traffic within hours.
openvpnOpenVPNms-sql-sMicrosoft-SQL-ServerExposure SQL Server on the internet is a credential-stuffing target and an xp_cmdshell risk.
ms-sql-mMicrosoft-SQL-MonitorIn practice The SQL Server browser service, which tells a caller which port a named instance listens on.
ncube-lmnCube License ManagerIn practice Registered to nCube’s licence manager; the world runs the Oracle TNS listener here.
Exposure A TNS listener answers version questions to anyone who connects.
pptppptpExposure PPTP’s authentication was broken in 1998 and MS-CHAPv2 is crackable at scale. Use WireGuard or IKEv2.
radiusRADIUSradius-acctRADIUS AccountingmqttMessage Queuing Telemetry Transport ProtocolExposure An MQTT broker with anonymous access publishes and accepts on every topic, which for building or vehicle telemetry means control.
shilpNo description in the registry.nfsNetwork File System - Sun MicrosystemsnfsNetwork File SystemIn practice Two assignments, and the one that matters is NFS.
Exposure NFS trusts the client’s idea of who the user is. Never across an untrusted network.
eforwardeforwardIn practice Registered to eforward; Apache ZooKeeper is what listens here in practice.
Exposure ZooKeeper with no authentication hands over the coordination state of whatever cluster it runs.
dockerDocker REST API (plain text)(no service name)ReservedExposure An unauthenticated Docker API is root on the host, one container run away. This is the classic cloud compromise.
docker-sDocker REST API (ssl)In practice The TLS-protected sibling of 2375.
etcd-clientetcd client communication(no service name)ReservedExposure etcd holds the entire state of a Kubernetes cluster, secrets included.
etcd-serveretcd server to server communication(no service name)ReservedhbciHBCIremoteware-clRemoteWare ClientIn practice Registered twice, to HBCI and RemoteWare; in practice this is the port every web framework picks for its development server.
ndl-aasActive API Server PortIn practice Registered to an Active API server; Squid picked it as its default and kept it.
msft-gcMicrosoft Global Catalogmsft-gc-sslMicrosoft Global Catalog with LDAP/SSLmysqlMySQLExposure MySQL exposed to the internet is scanned for continuously; bind it to localhost or a private subnet.
ms-wbt-serverMS WBT ServerIn practice MS WBT Server is Remote Desktop.
Exposure RDP open to the internet is how a large share of ransomware gets in. Put it behind a VPN or a gateway.
svnSubversionepmdErlang Port Mapper DaemonIn practice The Erlang port mapper, which fronts RabbitMQ and any Erlang or Elixir cluster.
Exposure A reachable epmd plus a guessed cookie is remote code execution on the node.
krb524KRB524nv-videoNV Video defaultIn practice Registered to krb524 and NV Video; better known as the default Metasploit handler port, which is a fact about attackers rather than about the registry.
ipsec-nat-tIPsec NAT-Traversalcommplex-mainNo description in the registry.In practice Registered as commplex-main with no description; in practice a Flask or Rails development server, and on macOS the AirPlay receiver.
sipSIPExposure An open SIP port is enumerated for extensions and then dialled through at your expense.
sipsSIP-TLSxmpp-clientXMPP Client Connection(no service name)Reservedxmpp-serverXMPP Server Connection(no service name)ReservedmdnsMulticast DNSExposure mDNS answers reveal hostnames, users and services, and it is an amplification source off-network.
postgresqlPostgreSQL DatabaseExposure PostgreSQL on a public address relies entirely on pg_hba.conf being right.
esmagentEnterprise Security AgentIn practice Registered as esmagent; in practice this is Kibana.
Exposure Kibana with no authentication in front of it is a read of every log you ship.
amqpsamqp protocol over TLS/SSLamqpAMQPExposure AMQP with the default guest credentials is a read and a write of every queue.
rfbRemote FramebufferIn practice RFB is the protocol; VNC is the product. Consecutive displays take 5901, 5902 and so on.
Exposure VNC’s own password is eight characters, sent with a weak challenge, and plenty of servers have none.
couchdbCouchDBExposure CouchDB shipped for years with an admin party by default; the internet found those instances.
wsmanWBEM WS-Management HTTPExposure WinRM over HTTP moves credentials and remote commands. 5986 does the same over TLS.
wsmansWBEM WS-Management HTTP over TLS/SSLx11X Window SystemIn practice X11 display :0, with :1 and :2 following on 6001 and 6002.
Exposure An X server accepting remote connections lets a client read every keystroke on the display.
redisAn advanced key-value cache and store(no service name)ReservedExposure Redis had no authentication at all by default until version 6, and its CONFIG command can write files. It is the most reliably exploited exposed database there is.
sun-sr-httpsService Registry Default HTTPS DomainIn practice Registered to Sun’s service registry; in practice the Kubernetes API server.
ircuIRCU(no service name)ReservedIn practice One assignment covers 6665 to 6669, which is why IRC networks span that block.
irdmiiRDMIIn practice Registered as irdmi; used by everything from Django’s development server to HTTP alternates.
http-altHTTP Alternate (see port 80)In practice The registry calls it HTTP Alternate and points at port 80. Tomcat, Jenkins and every reverse-proxy backend live here.
sunproxyadminSun Proxy Admin ServiceIn practice Registered to a Sun proxy admin service; in practice the second HTTP port, and Nexus or SonarQube by default.
pcsync-httpsPCsync HTTPSIn practice Registered to PCsync; in practice the TLS counterpart of 8080.
ddi-tcp-1NewsEDGE server TCP (TCP 1)ddi-udp-1NewsEDGE server UDP (UDP 1)In practice Registered to NewsEDGE; in practice Jupyter, and a second HTTP alternate.
Exposure A Jupyter server without a token is arbitrary code execution as whoever started it.
cslistenerCSlistenerIn practice Registered as cslistener; in practice PHP-FPM, SonarQube, MinIO and Portainer have all claimed it.
Exposure PHP-FPM speaking FastCGI to the internet has been a remote code execution path more than once.
websmWebSMIn practice Registered as websm; in practice Prometheus and Cockpit.
XmlIpcRegSvcXml-Ipc Server RegIn practice Registered to Xml-Ipc Server Reg; in practice Apache Kafka.
Exposure A Kafka broker with no authentication is a read and a write of every topic.
wap-wspWAP connectionless session serviceIn practice Registered as wap-wsp, a WAP session service; in practice Elasticsearch, with the transport protocol on 9300.
Exposure An open Elasticsearch cluster is the most common source of the leaked-database story.
gitgit pack transfer servicememcacheMemory cache serviceExposure Memcached over UDP gave the internet its largest recorded amplification attack in 2018, at 51,000 times the request size.
(no service name)UnassignedIn practice Unassigned in the registry — it falls inside a free block — and used by the RabbitMQ management plugin anyway. Customary rather than assigned.
Exposure The management UI is a web console over the broker with the default guest login on some builds.
dnpDNPdnpDistributed Network ProtocolIn practice DNP3, in electricity and water utilities.
Exposure DNP3 was designed for serial lines and trusts anything that speaks it.
mongodbMongo database system(no service name)ReservedExposure MongoDB bound to 0.0.0.0 with no authentication is the other half of the leaked-database story.
filenet-tmsFilenet TMSIn practice Registered to Filenet TMS; also the bottom of the ephemeral range on Linux, so a connection from it is usually just an outbound socket.
bacnetBuilding Automation and Control NetworksIn practice BACnet/IP, in building automation — lifts, HVAC, access control.
Exposure BACnet has no authentication. A device on a routed network can be commanded by anyone.
Service names, descriptions, transports and RFC references come from the IANA IANA Service Name and Transport Protocol Port Number Registry, taken on 2026-08-17 from a file last modified on 2026-08-11 and carrying 14,531 rows. The 116 ports here are a chosen subset of it. The ranges follow RFC 6335 §6. Lines marked in practice and exposure are ours rather than IANA’s: an assignment is a reservation in a registry, and it has never stopped anybody running something else on the port.
The sixteen-bit port space is divided into three parts. The first 1024 are the system ports, handed out only through formal review, and on Unix a process needs privilege to bind one. From 1024 to 49151 are the user ports, which anybody may apply to IANA for. Above that is the dynamic range, which is never assigned to anything because it is where your operating system takes the source port for each outgoing connection.
An assignment is a reservation in a registry, not an enforcement mechanism. Nothing stops software listening on a number registered to somebody else, and a great deal of well-known software does exactly that. The registry tells you what a number was set aside for; it cannot tell you what answered when you connected.
The gap between the two is wider than most people expect, and it is the reason this reference quotes the registry verbatim rather than tidying it. Port 1521 is assigned to a licence manager for a make of supercomputer, and the world runs an Oracle listener there. Port 9200 belongs to a wireless session protocol from the days of WAP, and search clusters have squatted on it for fifteen years. Kafka, Kubernetes and every framework’s development server are all somewhere in the same position.
Three names are registered on port 80, one of them for a transport nobody uses for web traffic. Port 465 carries three assignments, and the one that matters was declared deprecated and then formally restored for mail submission over TLS. Those entries look like mistakes and they are the record; correcting them here would be inventing a reference table, which is precisely what a sourced one is for.
The full registry runs to more than fourteen thousand rows and almost none of them are ever looked up. The entries here are the ones that turn up in firewall rules, scan output and incident tickets, with the service name, description, transports and cited RFCs copied from the registry file, and the date that file was taken recorded in the tool. A number missing from the list may simply be outside the subset rather than unassigned.
Two fields on each entry are not from the registry and say so. One records what a port is actually used for when that differs from its assignment; the other is a plain opinion about whether the service should ever be reachable from the internet. Keeping our judgement in separate fields from IANA’s data is what lets you trust the second column.
A short list accounts for a startling share of incidents. File sharing on 445 and remote desktop on 3389 are how a large fraction of ransomware arrives. Databases and caches bound to every interface — 6379, 27017, 11211, 9200 — are the leaked-database story in every one of its retellings, usually because the software shipped with no authentication and was never given any. An unauthenticated container API on 2375 is root on the host for anyone who can reach it.
The filter here that shows only those entries is not a scan and not a verdict about your network. It is a reading list: the ports where the default configuration and the internet are a bad combination, which is a different question from whether anything of yours is listening.
Because an assignment is advisory. Developers pick a free-looking number, it catches on, and the registry entry from 1998 stays where it is. Both facts are true at once, which is why this reference shows the registered name and what actually runs there.
Unix systems reserve the first 1024 ports for privileged processes, a rule from an era when a program on a low port could be assumed to be run by the machine’s owner. Modern deployments avoid it with a capability, a proxy in front, or a redirect from a higher port.
Every outbound connection needs a source port, and the kernel allocates one from that range for the duration. It is why a connection you started appears to come from a high number nobody assigned, and why nothing should ever be published there.
It means nothing accepted a connection from wherever you tested. The same service may be listening on another interface, reachable through a VPN, or exposed by a container mapping you have forgotten. Closed from here is not closed from everywhere.