Well-Known Ports Reference
System ports 0–1023
also called well-known
Assigned only through IETF review or IESG approval, and on Unix a process needs privilege to bind one.
User ports 1024–49151
also called registered
Assigned by IANA on request from anybody. An assignment here is a reservation, not an enforcement.
Dynamic ports 49152–65535
also called private or ephemeral
Never assigned to anything. The kernel allocates from this range for the client end of a connection.
A number matches by prefix, so 44 lists 443 and 445. Text matches the service name, the registry description and the RFC it cites.
System, user and dynamic ports together.
- 7tcp · udpSystem ports
echoEcho
- 19tcp · udpSystem ports
chargenCharacter Generator
Exposure Left open, chargen is an amplification source for reflected floods; there is no reason to run it today.
- 20tcp · udp · sctpSystem ports
ftp-dataFile Transfer [Default Data]ftp-dataFTP
- 21tcp · udp · sctpSystem ports
ftpFile Transfer Protocol [Control]ftpFTP
Exposure Control channel and credentials are plaintext. Use SFTP or FTPS instead of exposing it.
- 22tcp · udp · sctpSystem ports
sshThe Secure Shell (SSH) ProtocolsshSSH
In practice Also the transport for SFTP and scp, which are SSH subsystems rather than protocols of their own.
Exposure Safe to expose, but it will be brute-forced constantly; keys rather than passwords.
- 23tcp · udpSystem ports
telnetTelnet
Exposure Everything including the password crosses the wire in the clear. Nothing should answer here.
- 25tcp · udpSystem ports
smtpSimple Mail Transfer
In practice Server-to-server mail relay. Client submission belongs on 587, and many networks block outbound 25 entirely.
- 37tcp · udpSystem ports
timeTime
- 43tcp · udpSystem ports
nicnameWho Is
- 49tcp · udpSystem ports
tacacsLogin Host Protocol (TACACS)
- 53tcp · udpSystem ports
domainDomain Name Server
In practice UDP for ordinary queries, TCP for zone transfers and any answer too large for a datagram.
Exposure An open recursive resolver is an amplification weapon. Authoritative-only, or restricted to your own clients.
- 67tcp · udpSystem ports
bootpsBootstrap Protocol Server
- 68tcp · udpSystem ports
bootpcBootstrap Protocol Client
- 69tcp · udpSystem ports
tftpTrivial File Transfer
Exposure No authentication of any kind by design. Boot networks only, never routed.
- 79tcp · udpSystem ports
fingerFinger
Exposure Finger hands out account names to anyone who asks.
- 80tcp · udp · sctpSystem ports
httpWorld Wide Web HTTPwwwWorld Wide Web HTTPwww-httpWorld Wide Web HTTPhttpHTTP
In practice Three service names are registered on this one port; http is the one anybody uses.
Exposure Fine to expose, but serve a redirect to 443 rather than content.
- 88tcp · udpSystem ports
kerberosKerberos
- 102tcp · udpSystem ports
iso-tsapISO-TSAP Class 0
In practice Carries S7 traffic to Siemens PLCs, which is why it turns up in industrial network scans.
Exposure Industrial control traffic with no authentication worth the name. Never internet-facing.
- 110tcp · udpSystem ports
pop3Post Office Protocol - Version 3
Exposure Plaintext POP3. Prefer 995, or 110 with STARTTLS enforced.
- 111tcp · udpSystem ports
sunrpcSUN Remote Procedure Call
Exposure rpcbind tells a caller which ports the RPC services are on, and is an amplification source.
- 119tcp · udpSystem ports
nntpNetwork News Transfer Protocol
- 123tcp · udpSystem ports
ntpNetwork Time Protocol
Exposure An NTP server answering monlist to the internet is one of the largest amplification factors known.
- 135tcp · udpSystem ports
epmapDCE endpoint resolution
Exposure The Windows RPC endpoint mapper. Blocked at every perimeter for twenty years and still probed hourly.
- 137tcp · udpSystem ports
netbios-nsNETBIOS Name Service
Exposure NetBIOS name service leaks host and user names to anyone who asks.
- 138tcp · udpSystem ports
netbios-dgmNETBIOS Datagram Service
- 139tcp · udpSystem ports
netbios-ssnNETBIOS Session Service
Exposure SMB over NetBIOS. Along with 445, the pair that ransomware crews scan for first.
- 143tcp · udpSystem ports
imapInternet Message Access Protocol(no service name)Reserved
In practice The udp half of this port is Reserved rather than assigned, which is true of most modern mail ports.
- 161tcp · udpSystem ports
snmpSNMP
Exposure SNMP v1 and v2c authenticate with a community string in plaintext, and public is still the default.
- 162tcp · udpSystem ports
snmptrapSNMPTRAP
- 179tcp · udp · sctpSystem ports
bgpBorder Gateway ProtocolbgpBGP
Exposure BGP sessions belong between known peers with authentication, never open to the internet.
- 194tcp · udpSystem ports
ircInternet Relay Chat Protocol
- 389tcp · udpSystem ports
ldapLightweight Directory Access Protocol
Exposure Plaintext LDAP carries bind credentials in the clear; use 636 or StartTLS.
- 427tcp · udpSystem ports
svrlocServer Location
- 443tcp · udp · sctpSystem ports
httpshttp protocol over TLS/SSLhttpsHTTPS
- 445tcp · udpSystem ports
microsoft-dsMicrosoft-DS
In practice SMB direct over TCP, without the NetBIOS session layer of 139.
Exposure The single most attacked port on the internet. It has no business leaving your network.
- 465tcp · udpSystem ports
urdURL Rendezvous Directory for SSMsubmissionsMessage Submission over TLS protocoligmpv3liteIGMP over UDP for SSM
In practice Three assignments share this number. RFC 8314 restored it for implicit-TLS mail submission after years of it being called deprecated.
- 500tcp · udpSystem ports
isakmpisakmp
- 502tcp · udpSystem ports
mbapModbus Application Protocol
In practice Modbus/TCP, the protocol most industrial gear speaks.
Exposure Modbus has no authentication at all; a write is a write. Air-gapped or firewalled, never exposed.
- 514tcp · udpSystem ports
shellcmd like exec, but automatic authentication is performed as for login serversyslogNo description in the registry.
In practice Two different services: shell on tcp and syslog on udp. The syslog one is what people mean.
Exposure Plaintext syslog over UDP can be forged by anyone who can reach the collector.
- 515tcp · udpSystem ports
printerspooler
- 520tcp · udpSystem ports
efsextended file name serverrouterlocal routing process (on site); uses variant of Xerox NS routing information protocol - RIP
- 521tcp · udpSystem ports
ripngripng
- 546tcp · udpSystem ports
dhcpv6-clientDHCPv6 Client
- 547tcp · udpSystem ports
dhcpv6-serverDHCPv6 Server
- 548tcp · udpSystem ports
afpovertcpAFP over TCP
- 554tcp · udpSystem ports
rtspReal Time Streaming Protocol (RTSP)
- 587tcp · udpSystem ports
submissionMessage Submission
In practice The submission port: authenticated mail from a client, with STARTTLS.
- 593tcp · udpSystem ports
http-rpc-epmapHTTP RPC Ep Map
Exposure RPC over HTTP is a route into the same Windows RPC surface as 135.
- 623tcp · udpSystem ports
oob-ws-httpDMTF out-of-band web services management protocolasf-rmcpASF Remote Management and Control Protocol
In practice IPMI and BMC out-of-band management. Two different assignments on tcp and udp.
Exposure A BMC is a computer inside your computer with its own weak password. Management network only.
- 631tcp · udpSystem ports
ippIPP (Internet Printing Protocol)ippsInternet Printing Protocol over HTTPS
- 636tcp · udpSystem ports
ldapsldap protocol over TLS/SSL (was sldap)
- 646tcp · udpSystem ports
ldpLDP
- 873tcp · udpSystem ports
rsyncrsync
Exposure An rsync daemon with no auth module set is an anonymous read of whatever it exports.
- 989tcp · udpSystem ports
ftps-dataftp protocol, data, over TLS/SSL
- 990tcp · udpSystem ports
ftpsftp protocol, control, over TLS/SSL
- 993tcp · udpSystem ports
imapsIMAP over TLS protocol(no service name)Reserved
- 995tcp · udpSystem ports
pop3sPOP3 over TLS protocolpop3spop3 protocol over TLS/SSL (was spop3)
- 1080tcp · udpUser ports
socksSocks
Exposure An open SOCKS proxy will be found and used to launder somebody else’s traffic within hours.
- 1194tcp · udpUser ports
openvpnOpenVPN
- 1433tcp · udpUser ports
ms-sql-sMicrosoft-SQL-Server
Exposure SQL Server on the internet is a credential-stuffing target and an xp_cmdshell risk.
- 1434tcp · udpUser ports
ms-sql-mMicrosoft-SQL-Monitor
In practice The SQL Server browser service, which tells a caller which port a named instance listens on.
- 1521tcp · udpUser ports
ncube-lmnCube License Manager
In practice Registered to nCube’s licence manager; the world runs the Oracle TNS listener here.
Exposure A TNS listener answers version questions to anyone who connects.
- 1723tcp · udpUser ports
pptppptp
Exposure PPTP’s authentication was broken in 1998 and MS-CHAPv2 is crackable at scale. Use WireGuard or IKEv2.
- 1812tcp · udpUser ports
radiusRADIUS
- 1813tcp · udpUser ports
radius-acctRADIUS Accounting
- 1883tcp · udpUser ports
mqttMessage Queuing Telemetry Transport Protocol
Exposure An MQTT broker with anonymous access publishes and accepts on every topic, which for building or vehicle telemetry means control.
- 2049tcp · udp · sctpUser ports
shilpNo description in the registry.nfsNetwork File System - Sun MicrosystemsnfsNetwork File System
In practice Two assignments, and the one that matters is NFS.
Exposure NFS trusts the client’s idea of who the user is. Never across an untrusted network.
- 2181tcp · udpUser ports
eforwardeforward
In practice Registered to eforward; Apache ZooKeeper is what listens here in practice.
Exposure ZooKeeper with no authentication hands over the coordination state of whatever cluster it runs.
- 2375tcp · udpUser ports
dockerDocker REST API (plain text)(no service name)Reserved
Exposure An unauthenticated Docker API is root on the host, one container run away. This is the classic cloud compromise.
- 2376tcpUser ports
docker-sDocker REST API (ssl)
In practice The TLS-protected sibling of 2375.
- 2379tcp · udpUser ports
etcd-clientetcd client communication(no service name)Reserved
Exposure etcd holds the entire state of a Kubernetes cluster, secrets included.
- 2380tcp · udpUser ports
etcd-serveretcd server to server communication(no service name)Reserved
- 3000tcp · udpUser ports
hbciHBCIremoteware-clRemoteWare Client
In practice Registered twice, to HBCI and RemoteWare; in practice this is the port every web framework picks for its development server.
- 3128tcp · udpUser ports
ndl-aasActive API Server Port
In practice Registered to an Active API server; Squid picked it as its default and kept it.
- 3268tcp · udpUser ports
msft-gcMicrosoft Global Catalog
- 3269tcp · udpUser ports
msft-gc-sslMicrosoft Global Catalog with LDAP/SSL
- 3306tcp · udpUser ports
mysqlMySQL
Exposure MySQL exposed to the internet is scanned for continuously; bind it to localhost or a private subnet.
- 3389tcp · udpUser ports
ms-wbt-serverMS WBT Server
In practice MS WBT Server is Remote Desktop.
Exposure RDP open to the internet is how a large share of ransomware gets in. Put it behind a VPN or a gateway.
- 3690tcp · udpUser ports
svnSubversion
- 4369tcp · udpUser ports
epmdErlang Port Mapper Daemon
In practice The Erlang port mapper, which fronts RabbitMQ and any Erlang or Elixir cluster.
Exposure A reachable epmd plus a guessed cookie is remote code execution on the node.
- 4444tcp · udpUser ports
krb524KRB524nv-videoNV Video default
In practice Registered to krb524 and NV Video; better known as the default Metasploit handler port, which is a fact about attackers rather than about the registry.
- 4500tcp · udpUser ports
ipsec-nat-tIPsec NAT-Traversal
- 5000tcp · udpUser ports
commplex-mainNo description in the registry.
In practice Registered as commplex-main with no description; in practice a Flask or Rails development server, and on macOS the AirPlay receiver.
- 5060tcp · udp · sctpUser ports
sipSIP
Exposure An open SIP port is enumerated for extensions and then dialled through at your expense.
- 5061tcp · udp · sctpUser ports
sipsSIP-TLS
- 5222tcp · udpUser ports
xmpp-clientXMPP Client Connection(no service name)Reserved
- 5269tcp · udpUser ports
xmpp-serverXMPP Server Connection(no service name)Reserved
- 5353tcp · udpUser ports
mdnsMulticast DNS
Exposure mDNS answers reveal hostnames, users and services, and it is an amplification source off-network.
- 5432tcp · udpUser ports
postgresqlPostgreSQL Database
Exposure PostgreSQL on a public address relies entirely on pg_hba.conf being right.
- 5601tcp · udpUser ports
esmagentEnterprise Security Agent
In practice Registered as esmagent; in practice this is Kibana.
Exposure Kibana with no authentication in front of it is a read of every log you ship.
- 5671tcp · udpUser ports
amqpsamqp protocol over TLS/SSL
- 5672tcp · udp · sctpUser ports
amqpAMQP
Exposure AMQP with the default guest credentials is a read and a write of every queue.
- 5900tcp · udpUser ports
rfbRemote Framebuffer
In practice RFB is the protocol; VNC is the product. Consecutive displays take 5901, 5902 and so on.
Exposure VNC’s own password is eight characters, sent with a weak challenge, and plenty of servers have none.
- 5984tcp · udpUser ports
couchdbCouchDB
Exposure CouchDB shipped for years with an admin party by default; the internet found those instances.
- 5985tcp · udpUser ports
wsmanWBEM WS-Management HTTP
Exposure WinRM over HTTP moves credentials and remote commands. 5986 does the same over TLS.
- 5986tcp · udpUser ports
wsmansWBEM WS-Management HTTP over TLS/SSL
- 6000tcp · udpUser ports
x11X Window System
In practice X11 display :0, with :1 and :2 following on 6001 and 6002.
Exposure An X server accepting remote connections lets a client read every keystroke on the display.
- 6379tcp · udpUser ports
redisAn advanced key-value cache and store(no service name)Reserved
Exposure Redis had no authentication at all by default until version 6, and its CONFIG command can write files. It is the most reliably exploited exposed database there is.
- 6443tcp · udpUser ports
sun-sr-httpsService Registry Default HTTPS Domain
In practice Registered to Sun’s service registry; in practice the Kubernetes API server.
- 6665tcp · udpUser ports
ircuIRCU(no service name)Reserved
In practice One assignment covers 6665 to 6669, which is why IRC networks span that block.
- 8000tcp · udpUser ports
irdmiiRDMI
In practice Registered as irdmi; used by everything from Django’s development server to HTTP alternates.
- 8080tcp · udpUser ports
http-altHTTP Alternate (see port 80)
In practice The registry calls it HTTP Alternate and points at port 80. Tomcat, Jenkins and every reverse-proxy backend live here.
- 8081tcp · udpUser ports
sunproxyadminSun Proxy Admin Service
In practice Registered to a Sun proxy admin service; in practice the second HTTP port, and Nexus or SonarQube by default.
- 8443tcp · udpUser ports
pcsync-httpsPCsync HTTPS
In practice Registered to PCsync; in practice the TLS counterpart of 8080.
- 8888tcp · udpUser ports
ddi-tcp-1NewsEDGE server TCP (TCP 1)ddi-udp-1NewsEDGE server UDP (UDP 1)
In practice Registered to NewsEDGE; in practice Jupyter, and a second HTTP alternate.
Exposure A Jupyter server without a token is arbitrary code execution as whoever started it.
- 9000tcp · udpUser ports
cslistenerCSlistener
In practice Registered as cslistener; in practice PHP-FPM, SonarQube, MinIO and Portainer have all claimed it.
Exposure PHP-FPM speaking FastCGI to the internet has been a remote code execution path more than once.
- 9090tcp · udpUser ports
websmWebSM
In practice Registered as websm; in practice Prometheus and Cockpit.
- 9092tcp · udpUser ports
XmlIpcRegSvcXml-Ipc Server Reg
In practice Registered to Xml-Ipc Server Reg; in practice Apache Kafka.
Exposure A Kafka broker with no authentication is a read and a write of every topic.
- 9200tcp · udpUser ports
wap-wspWAP connectionless session service
In practice Registered as wap-wsp, a WAP session service; in practice Elasticsearch, with the transport protocol on 9300.
Exposure An open Elasticsearch cluster is the most common source of the leaked-database story.
- 9418tcp · udpUser ports
gitgit pack transfer service
- 11211tcp · udpUser ports
memcacheMemory cache service
Exposure Memcached over UDP gave the internet its largest recorded amplification attack in 2018, at 51,000 times the request size.
- 15672—User ports
(no service name)Unassigned
In practice Unassigned in the registry — it falls inside a free block — and used by the RabbitMQ management plugin anyway. Customary rather than assigned.
Exposure The management UI is a web console over the broker with the default guest login on some builds.
- 20000tcp · udp · sctpUser ports
dnpDNPdnpDistributed Network Protocol
In practice DNP3, in electricity and water utilities.
Exposure DNP3 was designed for serial lines and trusts anything that speaks it.
- 27017tcp · udpUser ports
mongodbMongo database system(no service name)Reserved
Exposure MongoDB bound to 0.0.0.0 with no authentication is the other half of the leaked-database story.
- 32768tcp · udpUser ports
filenet-tmsFilenet TMS
In practice Registered to Filenet TMS; also the bottom of the ephemeral range on Linux, so a connection from it is usually just an outbound socket.
- 47808tcp · udpUser ports
bacnetBuilding Automation and Control Networks
In practice BACnet/IP, in building automation — lifts, HVAC, access control.
Exposure BACnet has no authentication. A device on a routed network can be commanded by anyone.
Service names, descriptions, transports and RFC references come from the IANA IANA Service Name and Transport Protocol Port Number Registry, taken on 2026-08-17 from a file last modified on 2026-08-11 and carrying 14,531 rows. The 116 ports here are a chosen subset of it. The ranges follow RFC 6335 §6. Lines marked in practice and exposure are ours rather than IANA’s: an assignment is a reservation in a registry, and it has never stopped anybody running something else on the port — so finding 22 open tells you something is listening there, not that it is SSH.
Three ranges, and what an assignment actually means
The sixteen-bit port space is divided into three parts. The first 1024 are the system ports, handed out only through formal review, and on Unix a process needs privilege to bind one. From 1024 to 49151 are the user ports, which anybody may apply to IANA for. Above that is the dynamic range, which is never assigned to anything because it is where your operating system takes the source port for each outgoing connection.
An assignment is a reservation in a registry, not an enforcement mechanism. Nothing stops software listening on a number registered to somebody else, and a great deal of well-known software does exactly that. The registry tells you what a number was set aside for; it cannot tell you what answered when you connected.
Registered against merely customary
The gap between the two is wider than most people expect, and it is the reason this reference quotes the registry verbatim rather than tidying it. Port 1521 is assigned to a licence manager for a make of supercomputer, and the world runs an Oracle listener there. Port 9200 belongs to a wireless session protocol from the days of WAP, and search clusters have squatted on it for fifteen years. Kafka, Kubernetes and every framework’s development server are all somewhere in the same position.
Three names are registered on port 80, one of them for a transport nobody uses for web traffic. Port 465 carries three assignments, and the one that matters was declared deprecated and then formally restored for mail submission over TLS. Those entries look like mistakes and they are the record; correcting them here would be inventing a reference table, which is precisely what a sourced one is for.
A subset, chosen and labelled as one
The full registry runs to more than fourteen thousand rows and almost none of them are ever looked up. The entries here are the ones that turn up in firewall rules, scan output and incident tickets, with the service name, description, transports and cited RFCs copied from the registry file, and the date that file was taken recorded in the tool. A number missing from the list may simply be outside the subset rather than unassigned.
Two fields on each entry are not from the registry and say so. One records what a port is actually used for when that differs from its assignment; the other is a plain opinion about whether the service should ever be reachable from the internet. Keeping our judgement in separate fields from IANA’s data is what lets you trust the second column.
The ports that keep turning up in breach reports
A short list accounts for a startling share of incidents. File sharing on 445 and remote desktop on 3389 are how a large fraction of ransomware arrives. Databases and caches bound to every interface — 6379, 27017, 11211, 9200 — are the leaked-database story in every one of its retellings, usually because the software shipped with no authentication and was never given any. An unauthenticated container API on 2375 is root on the host for anyone who can reach it.
The filter here that shows only those entries is not a scan and not a verdict about your network. It is a reading list: the ports where the default configuration and the internet are a bad combination, which is a different question from whether anything of yours is listening.
Questions about ports and services
Why does my software listen on a port assigned to something else?
Because an assignment is advisory. Developers pick a free-looking number, it catches on, and the registry entry from 1998 stays where it is. Both facts are true at once, which is why this reference shows the registered name and what actually runs there.
Why can I not bind port 80 without administrator rights?
Unix systems reserve the first 1024 ports for privileged processes, a rule from an era when a program on a low port could be assumed to be run by the machine’s owner. Modern deployments avoid it with a capability, a proxy in front, or a redirect from a higher port.
What is the dynamic range actually for?
Every outbound connection needs a source port, and the kernel allocates one from that range for the duration. It is why a connection you started appears to come from a high number nobody assigned, and why nothing should ever be published there.
Does a closed port mean the service is secure?
It means nothing accepted a connection from wherever you tested. The same service may be listening on another interface, reachable through a VPN, or exposed by a container mapping you have forgotten. Closed from here is not closed from everywhere.
Sources
- IANA Service Name and Transport Protocol Port Number Registry — retrieved 17 August 2026
- RFC 6335: IANA procedures for the port number registry — retrieved 27 August 2026
Last reviewed 27 August 2026