common-ports-and-services.md (22671B)
1 --- 2 title: "Common Ports & Services (2026)" 3 description: "Field reference for common TCP/UDP ports and services — core internet, Windows/AD, web, database and remote-access mappings with confirmation tips." 4 category: enumeration 5 tags: ["enumeration", "port-scanning", "network"] 6 tools: ["Nmap", "ffuf", "smbmap", "NetExec", "ldapsearch"] 7 difficulty: beginner 8 updated: "2026-08-28" 9 source: "vault:Enumeration/Common Ports and Services Cheatsheet 2026.md" 10 --- 11 > [!important]+ The Rule That Prevents Bad Findings 12 > A port number is a **convention**, not proof of the application behind it. TCP and UDP are separate namespaces, services move to non-standard ports, and multiple products reuse popular ports such as 443, 8080, and 9000. Confirm with `nmap -sV`, a protocol handshake, TLS certificate/SNI, and application behaviour. 13 > 14 > Pairs with: Nmap Cheatsheet 2026, Nmap NSE Scripts Cheatsheet 2026, and NSE Guide. 15 16 --- 17 18 ## Port Number Ranges 19 20 | Range | IANA Class | Typical Use | 21 |---:|---|---| 22 | `0` | Reserved | Not a normal service port; some scanners only include it when explicitly requested | 23 | `1–1023` | System ports | Core protocols and privileged listeners on Unix-like systems | 24 | `1024–49151` | User/registered ports | Applications and registered vendor services | 25 | `49152–65535` | Dynamic/private ports | Client ephemeral ports, dynamic RPC, and private services | 26 27 > [!note]+ Same Number, Different Transport 28 > `53/tcp` and `53/udp` are different endpoints. DNS uses both; `514/udp` usually means syslog while `514/tcp` historically maps to the remote-shell service. Always record `port/protocol`, not the number alone. 29 30 --- 31 32 ## Core Internet and Infrastructure Services 33 34 | Port | Transport | Usual Service | What It Normally Does / Important Note | 35 |---:|:---:|---|---| 36 | 20 | TCP | FTP data | Active-mode FTP data channel | 37 | 21 | TCP | FTP control | File transfer commands and authentication | 38 | 22 | TCP | SSH | Secure shell; also SFTP and SCP | 39 | 23 | TCP | Telnet | Cleartext remote terminal; common on legacy/IoT equipment | 40 | 25 | TCP | SMTP | Server-to-server mail transfer; STARTTLS may upgrade encryption | 41 | 49 | TCP/UDP | TACACS+ / TACACS | Network-device AAA; TACACS+ normally uses TCP | 42 | 53 | TCP/UDP | DNS | UDP for most queries; TCP for large responses, zone transfers, and fallback | 43 | 67 | UDP | DHCP server | IPv4 address/configuration offers | 44 | 68 | UDP | DHCP client | IPv4 DHCP client endpoint | 45 | 69 | UDP | TFTP | Simple unauthenticated file transfer; PXE/network-device use | 46 | 80 | TCP | HTTP | Unencrypted web traffic or redirect to HTTPS | 47 | 88 | TCP/UDP | Kerberos | Authentication, especially Active Directory | 48 | 110 | TCP | POP3 | Mailbox retrieval without implicit TLS | 49 | 111 | TCP/UDP | rpcbind/portmapper | Maps ONC RPC programs; commonly exposes NFS-related services | 50 | 119 | TCP | NNTP | Usenet/news transfer | 51 | 123 | UDP | NTP | Network time synchronization | 52 | 135 | TCP | MS RPC endpoint mapper | Microsoft DCOM/RPC service discovery | 53 | 137 | UDP | NetBIOS name service | Legacy Windows name registration/resolution | 54 | 138 | UDP | NetBIOS datagram | Legacy Windows connectionless messaging/browsing | 55 | 139 | TCP | NetBIOS session/SMB | SMB over NetBIOS; legacy Windows file sharing | 56 | 143 | TCP | IMAP | Mailbox access without implicit TLS | 57 | 161 | UDP | SNMP | Device monitoring and management queries | 58 | 162 | UDP | SNMP trap | Unsolicited SNMP alerts to a manager | 59 | 179 | TCP | BGP | Inter-router Internet routing protocol | 60 | 389 | TCP/UDP | LDAP / CLDAP | Directory queries; UDP is commonly CLDAP discovery | 61 | 427 | TCP/UDP | SLP | Service Location Protocol discovery | 62 | 443 | TCP/UDP | HTTPS / HTTP/3 | HTTPS over TCP; QUIC/HTTP/3 commonly uses UDP 443 | 63 | 445 | TCP | SMB | Direct-hosted SMB for Windows file, printer, and AD services | 64 | 464 | TCP/UDP | Kerberos password change | `kpasswd` password set/change service | 65 | 500 | UDP | IKE/ISAKMP | IPsec VPN key exchange | 66 | 514 | UDP | Syslog | Traditional unencrypted log transport | 67 | 514 | TCP | rsh `shell` | Legacy remote shell assignment; modern syslog-over-TCP deployments also reuse it | 68 | 515 | TCP | LPD/LPR | Legacy network printing | 69 | 520 | UDP | RIP | IPv4 routing updates | 70 | 521 | UDP | RIPng | IPv6 routing updates | 71 | 546 | UDP | DHCPv6 client | IPv6 DHCP client endpoint | 72 | 547 | UDP | DHCPv6 server | IPv6 DHCP server/relay endpoint | 73 | 548 | TCP | AFP | Apple Filing Protocol | 74 | 554 | TCP/UDP | RTSP | Streaming-media session control | 75 | 587 | TCP | Mail submission | Authenticated client-to-mail-server submission with STARTTLS | 76 | 623 | UDP | IPMI RMCP | Out-of-band baseboard management traffic | 77 | 631 | TCP/UDP | IPP/CUPS | Modern network printing and print-service discovery | 78 | 636 | TCP | LDAPS | LDAP wrapped in TLS | 79 | 853 | TCP/UDP | Encrypted DNS | DNS over TLS on TCP; DNS over QUIC may use UDP | 80 | 873 | TCP | rsync | File synchronization; modules may be exposed anonymously | 81 | 989 | TCP | FTPS data | FTP data over implicit TLS | 82 | 990 | TCP | FTPS control | FTP control over implicit TLS | 83 | 993 | TCP | IMAPS | IMAP over implicit TLS | 84 | 995 | TCP | POP3S | POP3 over implicit TLS | 85 86 --- 87 88 ## Windows and Active Directory 89 90 | Port/Range | Transport | Service | AD / Windows Role | 91 |---:|:---:|---|---| 92 | 53 | TCP/UDP | DNS | AD-integrated DNS and domain-controller discovery | 93 | 88 | TCP/UDP | Kerberos | Ticket granting and service authentication | 94 | 123 | UDP | NTP | Domain time synchronization; Kerberos is time-sensitive | 95 | 135 | TCP | MSRPC endpoint mapper | Locates dynamic RPC services | 96 | 137–139 | TCP/UDP | NetBIOS | Legacy naming, datagrams, and SMB sessions | 97 | 389 | TCP/UDP | LDAP/CLDAP | Directory queries and DC discovery | 98 | 445 | TCP | SMB | Shares, named pipes, Group Policy, SYSVOL/NETLOGON | 99 | 464 | TCP/UDP | `kpasswd` | Kerberos password operations | 100 | 593 | TCP | RPC over HTTP | Microsoft RPC transport over HTTP | 101 | 636 | TCP | LDAPS | TLS-wrapped LDAP | 102 | 3268 | TCP | Global Catalog LDAP | Forest-wide partial directory search | 103 | 3269 | TCP | Global Catalog LDAPS | TLS-wrapped Global Catalog | 104 | 3389 | TCP/UDP | RDP | Remote Desktop; modern RDP also uses UDP | 105 | 5985 | TCP | WinRM HTTP | PowerShell remoting/WS-Management without TLS wrapper | 106 | 5986 | TCP | WinRM HTTPS | TLS-wrapped WinRM | 107 | 9389 | TCP | AD Web Services | PowerShell AD module and AD Administrative Center | 108 | 49152–65535 | TCP | Dynamic RPC | Default modern Windows high RPC endpoint range | 109 110 ```bash 111 # Targeted AD/DC service confirmation 112 sudo nmap -sS -sU -Pn -sV \ 113 -p T:53,88,135,139,389,445,464,593,636,3268,3269,3389,5985,5986,9389,U:53,88,123,137,138,389,464 \ 114 <target> 115 ``` 116 117 > [!tip]+ Recognizing a Domain Controller 118 > The combination of DNS, Kerberos, LDAP, SMB, Global Catalog, and AD Web Services is much more meaningful than any one open port. Use `-sV`, LDAP RootDSE, SMB discovery, DNS SRV records, and TLS certificates to confirm the role. 119 120 --- 121 122 ## Remote Administration, AAA, Proxies, and VPNs 123 124 | Port | Transport | Usual Service | Note | 125 |---:|:---:|---|---| 126 | 22 | TCP | SSH | Unix/network-device administration and tunnelling | 127 | 23 | TCP | Telnet | Cleartext legacy administration | 128 | 49 | TCP | TACACS+ | Central network-device authentication/authorization/accounting | 129 | 443 | TCP | SSL VPN / web admin | Common shared port; fingerprint the product | 130 | 500 | UDP | IKE | IPsec phase-one negotiation | 131 | 1080 | TCP | SOCKS proxy | Generic TCP proxy/pivot endpoint | 132 | 1194 | UDP/TCP | OpenVPN | UDP is the common default | 133 | 1701 | UDP | L2TP | Often paired with IPsec rather than exposed alone | 134 | 1723 | TCP | PPTP control | Data uses GRE IP protocol 47, not another TCP/UDP port | 135 | 1812 | UDP | RADIUS authentication | Network access authentication | 136 | 1813 | UDP | RADIUS accounting | Session/accounting records | 137 | 3128 | TCP | Squid HTTP proxy | Forward proxy and web cache | 138 | 3389 | TCP/UDP | RDP | Windows graphical administration | 139 | 4500 | UDP | IPsec NAT-T | Encapsulates IPsec ESP through NAT | 140 | 4899 | TCP | Radmin | Third-party Windows remote administration | 141 | 5900–5999 | TCP | VNC | Display numbers commonly map from 5900 upward | 142 | 5985/5986 | TCP | WinRM | Windows remote management over HTTP/HTTPS | 143 | 7547 | TCP | TR-069/CWMP | ISP management of customer-premises equipment | 144 | 8291 | TCP | MikroTik Winbox | RouterOS administration | 145 | 10000 | TCP | Webmin | Unix web administration console | 146 | 16992–16995 | TCP | Intel AMT | Out-of-band management, HTTP(S), and redirection services | 147 | 51820 | UDP | WireGuard | Common/default WireGuard tunnel port; configurable | 148 149 --- 150 151 ## File Sharing, Storage, and Printing 152 153 | Port | Transport | Service | Typical Use | 154 |---:|:---:|---|---| 155 | 20/21 | TCP | FTP | Legacy file transfer | 156 | 22 | TCP | SFTP/SCP | SSH-based encrypted file transfer | 157 | 69 | UDP | TFTP | PXE boot, firmware, and network-device configs | 158 | 111 | TCP/UDP | rpcbind | Discovers dynamic NFS/ONC RPC programs | 159 | 139/445 | TCP | SMB | Windows/Samba file and printer sharing | 160 | 515 | TCP | LPD | Legacy printer queue protocol | 161 | 548 | TCP | AFP | Legacy Apple file sharing | 162 | 631 | TCP/UDP | IPP | CUPS and modern printing | 163 | 873 | TCP | rsync | File synchronization modules | 164 | 989/990 | TCP | FTPS | Implicit-TLS FTP data/control | 165 | 2049 | TCP/UDP | NFS | Unix network file systems; modern NFS favors TCP | 166 | 3260 | TCP | iSCSI | Block-storage transport | 167 | 9100 | TCP | JetDirect/raw printing | Direct printer data socket; also reused by node_exporter | 168 169 --- 170 171 ## Databases, Search, and Caches 172 173 | Port | Transport | Usual Product/Protocol | Note | 174 |---:|:---:|---|---| 175 | 1433 | TCP | Microsoft SQL Server | Database engine endpoint | 176 | 1434 | UDP | SQL Server Browser | Instance/port discovery | 177 | 1521 | TCP | Oracle TNS Listener | Oracle database connection broker | 178 | 3050 | TCP | Firebird | Firebird relational database | 179 | 3306 | TCP | MySQL/MariaDB | MySQL protocol | 180 | 5432 | TCP | PostgreSQL | PostgreSQL wire protocol | 181 | 5984 | TCP | CouchDB | HTTP API | 182 | 6379 | TCP | Redis | In-memory data store; TLS is often configured elsewhere | 183 | 7474 | TCP | Neo4j HTTP | Neo4j browser/HTTP API | 184 | 7687 | TCP | Neo4j Bolt | Native Bolt protocol | 185 | 8086 | TCP | InfluxDB | HTTP API | 186 | 8123 | TCP | ClickHouse HTTP | HTTP query interface | 187 | 8529 | TCP | ArangoDB | HTTP API | 188 | 9000 | TCP | ClickHouse native | Also heavily reused by unrelated products | 189 | 9042 | TCP | Cassandra CQL | Native Cassandra client protocol | 190 | 9200 | TCP | Elasticsearch HTTP | REST API | 191 | 9300 | TCP | Elasticsearch transport | Cluster/node transport | 192 | 11211 | TCP/UDP | Memcached | Distributed memory cache; UDP should rarely be exposed | 193 | 27017 | TCP | MongoDB | MongoDB client protocol | 194 195 > [!warning]+ Databases Should Rarely Be Internet-Facing 196 > An open database port is not automatically unauthenticated. Confirm binding scope, TLS, authentication, authorization, and network policy with approved credentials rather than inferring exposure from the port alone. 197 198 --- 199 200 ## Containers, Orchestration, and DevOps 201 202 | Port | Transport | Usual Product/Service | Security-Relevant Note | 203 |---:|:---:|---|---| 204 | 2375 | TCP | Docker API (plain HTTP) | Unauthenticated exposure can amount to host control | 205 | 2376 | TCP | Docker API (TLS) | Confirm mutual TLS and authorization | 206 | 2377 | TCP | Docker Swarm management | Manager control plane | 207 | 2379 | TCP | etcd client API | Kubernetes state/config data | 208 | 2380 | TCP | etcd peer traffic | Cluster replication | 209 | 3000 | TCP | Grafana / dev web server | Product convention, not reliable identification | 210 | 4646 | TCP | Nomad HTTP API | HashiCorp Nomad control/API | 211 | 4789 | UDP | VXLAN | Overlay-network encapsulation | 212 | 5000 | TCP | Container registry / dev web | Frequently reused; fingerprint it | 213 | 5601 | TCP | Kibana | Elastic web interface | 214 | 6443 | TCP | Kubernetes API | Kubernetes control-plane API | 215 | 8001 | TCP | Kubernetes API proxy | Common local `kubectl proxy` listener | 216 | 8200 | TCP | HashiCorp Vault API | Secrets-management API | 217 | 8500 | TCP | Consul HTTP API | Service catalog/control API | 218 | 8501 | TCP | Consul HTTPS API | TLS-wrapped Consul HTTP API | 219 | 8600 | TCP/UDP | Consul DNS | Service discovery through DNS | 220 | 9000 | TCP | Portainer legacy / SonarQube / apps | Highly ambiguous convention | 221 | 9090 | TCP | Prometheus | Metrics query and web UI | 222 | 9093 | TCP | Alertmanager | Prometheus alert management | 223 | 9100 | TCP | Prometheus node_exporter | Conflicts with raw printer convention | 224 | 9418 | TCP | Git protocol | Unencrypted native Git transport | 225 | 10250 | TCP | Kubelet API | Node-level Kubernetes API | 226 | 15672 | TCP | RabbitMQ management | HTTP management UI/API | 227 | 50000 | TCP | Jenkins inbound agent | Configurable; not every Jenkins uses it | 228 229 --- 230 231 ## Messaging, Queues, and Service Discovery 232 233 | Port | Transport | Service | Typical Role | 234 |---:|:---:|---|---| 235 | 1883 | TCP | MQTT | Unencrypted IoT/message broker traffic | 236 | 2181 | TCP | ZooKeeper | Distributed coordination | 237 | 3478 | TCP/UDP | STUN/TURN | NAT traversal for real-time communications | 238 | 3702 | UDP | WS-Discovery | Windows/printer/device discovery multicast | 239 | 4222 | TCP | NATS | Client messaging endpoint | 240 | 4369 | TCP | Erlang EPMD | Discovers Erlang distributed-node ports | 241 | 5349 | TCP/UDP | TURN over TLS/DTLS | Encrypted relay service | 242 | 5353 | UDP | mDNS | `.local` multicast service discovery | 243 | 5355 | TCP/UDP | LLMNR | Windows local-link name resolution | 244 | 5671 | TCP | AMQP over TLS | TLS-wrapped message queue protocol | 245 | 5672 | TCP | AMQP | RabbitMQ and other AMQP brokers | 246 | 5683 | UDP | CoAP | Constrained/IoT application protocol | 247 | 5684 | UDP | CoAP over DTLS | Encrypted CoAP | 248 | 8222 | TCP | NATS monitoring | HTTP monitoring endpoint | 249 | 8883 | TCP | MQTT over TLS | TLS-wrapped MQTT | 250 | 9092 | TCP | Apache Kafka | Broker/client protocol | 251 | 25672 | TCP | Erlang/RabbitMQ distribution | RabbitMQ inter-node traffic | 252 | 61613 | TCP | STOMP | Messaging protocol, often ActiveMQ | 253 | 61616 | TCP | ActiveMQ OpenWire | ActiveMQ broker transport | 254 255 --- 256 257 ## Email and Collaboration 258 259 | Port | Transport | Service | Typical Use | 260 |---:|:---:|---|---| 261 | 25 | TCP | SMTP | Mail relay/server-to-server transfer | 262 | 110 | TCP | POP3 | Mail retrieval with optional STARTTLS | 263 | 143 | TCP | IMAP | Mailbox access with optional STARTTLS | 264 | 465 | TCP | Submissions over TLS | Implicit-TLS mail submission | 265 | 587 | TCP | Message submission | Authenticated submission, normally STARTTLS | 266 | 993 | TCP | IMAPS | IMAP over implicit TLS | 267 | 995 | TCP | POP3S | POP3 over implicit TLS | 268 | 2525 | TCP | Alternate SMTP/submission | Common provider convention, not universal | 269 | 4190 | TCP | ManageSieve | Server-side mail-filter management | 270 | 5222 | TCP | XMPP client | Client-to-server chat/federation ecosystem | 271 | 5269 | TCP | XMPP server | Server-to-server federation | 272 273 --- 274 275 ## Voice, Video, and Real-Time Communications 276 277 | Port/Range | Transport | Service | Typical Use | 278 |---:|:---:|---|---| 279 | 1720 | TCP | H.323 | Call signalling | 280 | 2427 | UDP | MGCP gateway | Media gateway control | 281 | 3478 | TCP/UDP | STUN/TURN | NAT discovery and media relay | 282 | 4569 | UDP | IAX2 | Asterisk inter-server/client VoIP | 283 | 5060 | TCP/UDP | SIP | Unencrypted signalling | 284 | 5061 | TCP | SIP over TLS | TLS-wrapped SIP signalling | 285 | 5349 | TCP/UDP | TURN over TLS/DTLS | Encrypted media relay | 286 | 16384–32767 | UDP | RTP/RTCP convention | Dynamic voice/video media range; implementation-specific | 287 288 --- 289 290 ## Monitoring and Logging 291 292 | Port | Transport | Service | Typical Use | 293 |---:|:---:|---|---| 294 | 161/162 | UDP | SNMP / traps | Polling and asynchronous device alerts | 295 | 514 | UDP | Syslog | Traditional unencrypted logs | 296 | 2003 | TCP | Graphite Carbon | Plaintext metric ingestion | 297 | 5666 | TCP | NRPE | Nagios remote plugin execution | 298 | 6514 | TCP | Syslog over TLS | Encrypted log transport | 299 | 8125 | UDP | StatsD | Metric ingestion | 300 | 9090 | TCP | Prometheus | Metrics/query web service | 301 | 9093 | TCP | Alertmanager | Alert routing/management | 302 | 9100 | TCP | node_exporter | Host metrics; conflicts with JetDirect convention | 303 | 10050 | TCP | Zabbix agent | Agent checks | 304 | 10051 | TCP | Zabbix server/trapper | Server/proxy collection endpoint | 305 306 --- 307 308 ## ICS / OT and Building Automation 309 310 > [!danger]+ Fragile Environments 311 > Do not assume ordinary IT scan rates are safe for PLCs, safety systems, field devices, printers, or building controllers. Prefer passive asset data and vendor-approved, rate-limited probes under explicit OT rules of engagement. 312 313 | Port | Transport | Protocol/Product Family | Typical Environment | 314 |---:|:---:|---|---| 315 | 102 | TCP | ISO-TSAP / Siemens S7 | Siemens PLC programming/communications | 316 | 502 | TCP | Modbus/TCP | PLC, HMI, energy, and industrial control | 317 | 1911 | TCP | Niagara Fox | Building automation | 318 | 1962 | TCP/UDP | PCWorx | Phoenix Contact PLC engineering | 319 | 2404 | TCP | IEC 60870-5-104 | Electric utility telecontrol | 320 | 4840 | TCP | OPC UA | Industrial interoperability/data modelling | 321 | 5094 | TCP/UDP | HART-IP | Industrial field-device communications | 322 | 9600 | TCP/UDP | OMRON FINS | OMRON PLC communications | 323 | 20000 | TCP/UDP | DNP3 | Utility/SCADA telemetry and control | 324 | 34962–34964 | UDP | PROFINET | Discovery, RPC/context, and alarms | 325 | 44818 | TCP/UDP | EtherNet/IP | Common Industrial Protocol (CIP) | 326 | 47808 | UDP | BACnet/IP | Building automation and HVAC | 327 328 --- 329 330 ## Frequently Ambiguous Web and Application Ports 331 332 | Port | Common Possibilities | Do Not Assume | 333 |---:|---|---| 334 | 3000 | Grafana, Rails/Node/React dev server | That it is Grafana | 335 | 5000 | Flask/dev server, Docker Registry, UPnP control, vendor API | That HTTP implies one product | 336 | 8000 | Django/dev HTTP, appliance UI, streaming service | That it is “just alternate HTTP” | 337 | 8008 | Alternate HTTP, Chromecast-related traffic, appliance UI | Product identity | 338 | 8080 | Proxy, Tomcat, Jenkins, alternate HTTP/admin UI | That it is always a web proxy | 339 | 8081 | Artifact repository, alternate admin UI, dev server | Nexus/Artifactory without fingerprints | 340 | 8443 | Alternate HTTPS, Kubernetes/dashboard/appliance UI | That TLS identifies the application | 341 | 8888 | Jupyter, alternate HTTP, proxy/control UI | That an exposed notebook exists | 342 | 9000 | ClickHouse, SonarQube, Portainer legacy, PHP-FPM/vendor apps | Any single product | 343 | 9100 | JetDirect raw printing or Prometheus node_exporter | Printer versus metrics service | 344 | 9443 | Alternate HTTPS, container/admin UI | Product or authorization model | 345 346 ```bash 347 # Identify an ambiguous service instead of trusting the port label 348 nmap -Pn -n -sV --version-all --reason -p3000,5000,8000,8080,8443,9000,9100 <target> 349 350 # Add web/TLS metadata where applicable 351 nmap -Pn -n -sV -p3000,5000,8000,8080,8443,9000,9100 \ 352 --script=http-title,http-headers,ssl-cert <target> 353 ``` 354 355 --- 356 357 ## High-Value UDP Triage List 358 359 ```bash 360 sudo nmap -sU -Pn -n -sV --reason \ 361 -p53,67,68,69,88,111,123,137,138,161,162,389,500,514,520,521,623,1434,1701,1812,1813,1900,2049,3478,3702,4500,4789,5060,5353,5355,5683,11211,20000,34962-34964,44818,47808,51820 \ 362 <target> 363 ``` 364 365 | UDP Port | First Thought | Confirmation Idea | 366 |---:|---|---| 367 | 53 | DNS | `dig`, `dns-nsid`, recursion/authoritative checks | 368 | 69 | TFTP | Request a known in-scope filename; avoid blind writes | 369 | 123 | NTP | `ntpq`, `ntp-info` | 370 | 161 | SNMP | `snmpwalk` with an approved community/credential | 371 | 500/4500 | IPsec VPN | IKE fingerprinting; confirm NAT-T | 372 | 623 | IPMI | RMCP/IPMI version and cipher checks | 373 | 1434 | SQL Browser | Query instance names/ports | 374 | 1900 | SSDP/UPnP | Multicast discovery and device description XML | 375 | 5353 | mDNS | Browse `.local` service records | 376 | 11211 | Memcached | Confirm UDP enablement; amplification exposure is high risk | 377 378 --- 379 380 ## IP Protocol Numbers Are Not Ports 381 382 | IP Protocol Number | Protocol | Why You May See It | 383 |---:|---|---| 384 | 1 | ICMP | IPv4 errors and diagnostics | 385 | 2 | IGMP | IPv4 multicast membership | 386 | 4 | IP-in-IP | IP tunnelling | 387 | 6 | TCP | Transmission Control Protocol | 388 | 17 | UDP | User Datagram Protocol | 389 | 41 | IPv6 encapsulation | IPv6-in-IPv4 tunnels | 390 | 47 | GRE | PPTP data and generic routing encapsulation | 391 | 50 | ESP | IPsec encrypted payload | 392 | 51 | AH | IPsec authentication header | 393 | 58 | ICMPv6 | IPv6 discovery, errors, and diagnostics | 394 | 89 | OSPF | Interior routing protocol | 395 | 132 | SCTP | Telecom/signalling and specialized applications | 396 397 ```bash 398 # Scan IP protocol numbers rather than TCP/UDP ports 399 sudo nmap -sO --reason <target> 400 ``` 401 402 --- 403 404 ## From an Open Port to the Right Next Tool 405 406 | Service | Confirm / Enumerate With | 407 |---|---| 408 | DNS | `dig`, `host`, `dnsrecon`, Nmap `dns-*` scripts | 409 | FTP | `ftp`, `curl`, `ftp-anon`, banner and TLS inspection | 410 | SSH | `ssh -vv`, `ssh-keyscan`, `ssh-audit`, SSH NSE scripts | 411 | HTTP(S) | `curl`, browser/devtools, `whatweb`, `ffuf`, HTTP/TLS NSE | 412 | SMB | `smbclient`, `enum4linux-ng`, `netexec`, `smbmap`, SMB NSE | 413 | LDAP | `ldapsearch`, RootDSE query, TLS certificate review | 414 | Kerberos | DNS SRV records, `kinit`, approved AD enumeration tooling | 415 | SNMP | `snmpwalk`, `snmpget`, SNMP NSE scripts | 416 | NFS | `rpcinfo`, `showmount`, NFS NSE scripts | 417 | SMTP | `openssl s_client`, SMTP dialogue, `smtp-*` NSE scripts | 418 | RDP | `xfreerdp`, RDP encryption/NTLM-info NSE | 419 | WinRM | PowerShell remoting or `evil-winrm` with approved credentials | 420 | Database | Native read-only client with an approved account; capture TLS/auth settings | 421 422 --- 423 424 ## Quick Reference Scan Sets 425 426 ```bash 427 # Common TCP infrastructure and administration 428 sudo nmap -sS -Pn -n -sV \ 429 -p21,22,23,25,49,53,80,88,110,111,135,139,143,179,389,443,445,464,514,515,548,554,587,631,636,873,990,993,995,1080,1194,1433,1521,1723,2049,2375,2376,3000,3128,3260,3268,3269,3306,3389,5432,5672,5900,5985,5986,6379,6443,8080,8443,8883,9000,9090,9100,9200,10000,10250,11211,27017 \ 430 <target> 431 432 # Core UDP infrastructure 433 sudo nmap -sU -Pn -n -sV \ 434 -p53,67,68,69,88,111,123,137,138,161,162,389,500,514,520,521,623,1434,1701,1812,1813,1900,2049,3478,3702,4500,4789,5060,5353,5355,5683,51820 \ 435 <target> 436 ``` 437 438 --- 439 440 ## References 441 442 1. [IANA Service Name and Transport Protocol Port Number Registry](https://www.iana.org/assignments/service-names-port-numbers/) 443 2. [RFC 6335 — Service Name and Port Number Procedures](https://www.rfc-editor.org/rfc/rfc6335) 444 3. [Nmap `nmap-services` Database](https://nmap.org/book/nmap-services.html) 445 4. [Nmap Service and Version Detection](https://nmap.org/book/vscan.html) 446 5. [Nmap Port Specification](https://nmap.org/book/man-port-specification.html)