~/port-references

Port References

CPTS Notes10 min read

Service-to-port map for enumeration. Ports are TCP unless the row says UDP. Services move, so always check with -sV. A port is only what the banner proves it is.

Always check first

The high-value set worth prioritising on any target.

Port Service Why it matters
21 FTP Anonymous login, file read/write.
22 SSH Version-specific bugs, key or password auth, tunneling.
25 SMTP User enumeration (VRFY, EXPN, RCPT).
53 DNS Zone transfer, subdomain and host names.
80 / 443 HTTP / HTTPS Largest attack surface. Directory brute, vhosts, app bugs.
88 Kerberos AD present. AS-REP roast, user enumeration.
111 rpcbind Maps to NFS and other RPC services.
135 / 139 / 445 MSRPC / NetBIOS / SMB Shares, users, RCE.
161 (UDP) SNMP Community strings leak users, processes, routes.
389 / 636 LDAP / LDAPS AD objects, users, groups.
1433 / 3306 / 5432 MSSQL / MySQL / PostgreSQL Weak creds, command execution.
3389 RDP Credential access to Windows.
5985 / 5986 WinRM Remote shell with valid creds (evil-winrm).

File sharing and transfer

Port Proto Service Notes
20 TCP FTP data Active-mode data channel.
21 TCP FTP control Anonymous login, banner leaks version.
69 UDP TFTP No auth, no listing. Guess filenames.
111 TCP/UDP rpcbind / portmapper Lists RPC services. Feed into showmount.
135 TCP MSRPC Endpoint mapper. rpcdump, DCOM.
137 UDP NetBIOS name nmblookup, name resolution.
138 UDP NetBIOS datagram Browser service.
139 TCP NetBIOS session SMB over NetBIOS.
445 TCP SMB / CIFS Shares, users, EternalBlue.
512 TCP rexec Remote exec, cleartext creds.
513 TCP rlogin Trust-based login, .rhosts.
514 TCP rsh Remote shell, no auth if trusted.
548 TCP AFP Apple filing. nmap afp-* scripts.
873 TCP rsync Often anonymous module listing and file pull.
2049 TCP/UDP NFS showmount -e, mount exports, no_root_squash.
2121 TCP FTP (alt) Secondary FTP instance.

Remote access and shells

Port Proto Service Notes
22 TCP SSH Auth methods, version bugs, port forwarding.
23 TCP Telnet Cleartext login, banner.
512-514 TCP r-services See file-sharing table. Trust abuse.
3389 TCP RDP xfreerdp, NLA check, BlueKeep on old hosts.
5800 TCP VNC over HTTP Java VNC applet.
5900 TCP VNC Weak or no password, vncviewer.
5985 TCP WinRM HTTP evil-winrm, crackmapexec winrm.
5986 TCP WinRM HTTPS TLS variant of WinRM.
6000-6009 TCP X11 Keystroke capture, screenshots if open.
47001 TCP WinRM (WSMan listener) Windows remote management.

Web and application servers

Port Proto Service Notes
80 TCP HTTP Primary web surface.
443 TCP HTTPS TLS web. Check certificate for hostnames.
280 TCP http-mgmt Management HTTP.
591 TCP FileMaker HTTP Alternate web.
593 TCP HTTP-RPC-EPMAP RPC over HTTP.
832 TCP NetWare HTTP Rare web admin.
981 TCP HTTPS (alt) Firewall admin panels.
1311 TCP Dell OpenManage Web admin.
2082 / 2083 TCP cPanel HTTP / HTTPS.
2086 / 2087 TCP WHM HTTP / HTTPS.
2095 / 2096 TCP Webmail HTTP / HTTPS.
3000 TCP Node / Grafana / dev App dev servers.
3128 TCP Squid proxy Proxy, may reach internal hosts.
4443 TCP HTTPS (alt) Admin consoles.
4848 TCP GlassFish admin Default creds, WAR deploy.
5000 TCP Flask / UPnP / Docker registry Context-dependent.
7001 TCP WebLogic Deserialization RCE.
7070 TCP RealServer / app HTTP variants.
8000 TCP HTTP (alt) Dev and admin apps.
8008 TCP HTTP (alt) Embedded web.
8009 TCP AJP13 Tomcat AJP. Ghostcat file read.
8080 TCP HTTP proxy / Tomcat Manager panel, WAR upload.
8081 TCP HTTP (alt) JForum, Nexus, misc.
8180 TCP Tomcat (alt) Manager panel.
8443 TCP HTTPS (alt) Tomcat, VMware, admin.
8500 TCP Consul / ColdFusion Config store or app server.
8888 TCP HTTP (alt) Jupyter, admin panels.
9000 TCP PHP-FPM / SonarQube FastCGI or app.
9090 TCP Openfire / Prometheus Admin console.
9200 / 9300 TCP Elasticsearch REST API and transport. Data exposure.
10000 TCP Webmin RCE on old versions.

Mail

Port Proto Service Notes
25 TCP SMTP User enumeration, open relay.
110 TCP POP3 Cleartext mail retrieval.
143 TCP IMAP Cleartext mailbox access.
465 TCP SMTPS SMTP over TLS.
587 TCP SMTP submission Authenticated mail submission.
993 TCP IMAPS IMAP over TLS.
995 TCP POP3S POP3 over TLS.

Name, directory, and auth services

Port Proto Service Notes
53 TCP/UDP DNS Zone transfer (axfr), reverse lookups.
88 TCP Kerberos AS-REP roast, TGT requests.
389 TCP/UDP LDAP Anonymous bind, AD objects.
464 TCP Kerberos kpasswd Password change service.
636 TCP LDAPS LDAP over TLS.
749 TCP Kerberos admin kadmin.
3268 TCP LDAP Global Catalog Forest-wide AD queries.
3269 TCP LDAP GC over TLS TLS global catalog.
9389 TCP AD Web Services ADWS, PowerShell AD module.

Databases

Port Proto Service Notes
1433 TCP MSSQL xp_cmdshell, mssqlclient.py.
1434 UDP MSSQL Browser Instance discovery.
1521 TCP Oracle TNS SID brute, odat.
1830 TCP Oracle (alt) Secondary listener.
3306 TCP MySQL / MariaDB Weak creds, INTO OUTFILE.
5432 TCP PostgreSQL COPY ... PROGRAM for RCE.
5984 TCP CouchDB REST API, unauth data.
6379 TCP Redis No auth by default, key write to RCE.
7474 / 7687 TCP Neo4j HTTP browser and Bolt.
9042 TCP Cassandra CQL native transport.
11211 TCP/UDP Memcached Unauth data dump, amplification.
27017 / 27018 TCP MongoDB Unauth access on old configs.

SNMP and network management

Port Proto Service Notes
161 UDP SNMP snmpwalk with public. Leaks users, processes, ARP.
162 UDP SNMP trap Trap receiver.
199 TCP SMUX SNMP multiplexer.
623 UDP IPMI / BMC Hash dump (ipmi-dumphashes).
2000 TCP Cisco SCCP VoIP signalling.
4786 TCP Cisco Smart Install Config theft, RCE.
5060 / 5061 TCP/UDP SIP VoIP, user enumeration.

Messaging, orchestration, and misc

Port Proto Service Notes
79 TCP Finger User enumeration on old Unix.
113 TCP ident Returns service owner.
123 UDP NTP ntpq, monlist amplification.
179 TCP BGP Routing, rare on HTB-like boxes.
500 UDP IKE / IPsec ike-scan, VPN fingerprint.
502 TCP Modbus ICS/SCADA.
515 TCP LPD Printing service.
631 TCP IPP / CUPS Printer admin.
1099 TCP Java RMI Deserialization RCE.
1723 TCP PPTP VPN, hash capture.
1883 TCP MQTT IoT messaging, often unauth.
2181 TCP ZooKeeper Config leak, envi command.
2375 / 2376 TCP Docker API Unauth 2375 = host RCE.
3632 TCP distcc Command execution (CVE-2004-2687).
4369 TCP EPMD (Erlang) Cookie auth, RabbitMQ pairing.
5222 TCP XMPP Chat, user enumeration.
5353 UDP mDNS Local service discovery.
5355 UDP LLMNR Poison for hash capture (responder).
5671 / 5672 TCP AMQP / RabbitMQ Message broker, default creds.
6443 TCP Kubernetes API Cluster control, token abuse.
8140 TCP Puppet Config management.
8161 TCP ActiveMQ Web console, CVE-2016-3088.
9092 TCP Kafka Broker, topic access.
9100 TCP JetDirect Raw printing, PJL abuse.
15672 TCP RabbitMQ mgmt Web console, guest:guest.
44818 TCP/UDP EtherNet/IP ICS/SCADA.

Common backdoor and shell ports

Ports that often mean an attacker already touched the box, or a listener you set.

Port Meaning
1080 SOCKS proxy, sometimes a pivot.
1337 Common custom backdoor.
4444 Metasploit default handler.
6666 / 6667 IRC, historic botnet C2.
12345 NetBus.
31337 Back Orifice, “elite” backdoor.

Fast lookups

Nmap prints the service guess from /etc/services. Read the real name of a numeric port:

grep -w 6379 /etc/services

Search a service by name to find its default port:

grep -iw redis /etc/services

Do not trust the default map. Run -sV and read the banner. A service on a non-standard port is common on HTB-like boxes and is exactly what a quick scan misses.