Most Common TCP and UDP Ports and Their Services (With Security Notes)
Understanding the list of common TCP and UDP ports and the services they correspond to is essential for ethical hackers, penetration testers, network administrators, and cybersecurity professionals. These ports, such as FTP (21), SSH (22), HTTP (80), and HTTPS (443), enable communication between devices and software across a network. Unsecured or open ports can often be exploited by attackers, which is why knowing their purpose, usage, and associated protocols is critical for maintaining secure network architecture and for conducting reconnaissance during vulnerability assessments. This blog covers a detailed port-to-service mapping, real-world hacking scenarios, and FAQs to help you master port-based network communication and security fundamentals.
Quick answer: A port is a 16-bit number (0 to 65535) that tells a computer which service should receive a packet. The ones every network and security student should know are 22 (SSH), 25 (SMTP), 53 (DNS), 80 (HTTP), 443 (HTTPS), 445 (SMB), 3306 (MySQL) and 3389 (RDP). Each runs over TCP, UDP or both, and each is a thing to secure, not just memorise.
Key takeaways
- Ports 0 to 1023 are well-known, 1024 to 49151 are registered, and 49152 to 65535 are dynamic. The official list is kept by IANA.
- A port number only suggests a service. Anyone can run SSH on port 2222 or a web server on 22, so always confirm with service detection.
- Learn each port with three facts: what service, TCP or UDP, and whether it should ever be reachable from the internet.
- Defenders use the same list to write firewall rules and spot odd traffic. Scanning ports you do not own or have written permission to test is illegal in India.
What is a network port?
A port is a number that identifies one service on a machine. The IP address finds the computer; the port finds the program on it that should handle the traffic.
Think of an office building. The IP address is the building's address. The port is the room number. A web server waits in room 443, a mail server in room 25. When your browser connects to a site over HTTPS, it sends the request to port 443 of the server's IP address, and the operating system hands it to whichever program is listening there.
Your own computer also uses a port for every connection it opens. These are short-lived "ephemeral" ports from the high range, picked automatically. A connection is really identified by four values: source IP, source port, destination IP and destination port.
What are the three port ranges?
Port numbers run from 0 to 65535 and are split into three ranges by IANA, the body that maintains the official service name and port number registry.
- Well-known ports (0 to 1023): assigned to core services such as HTTP, SSH and DNS. On Linux, only a privileged process can listen on these.
- Registered ports (1024 to 49151): assigned to specific applications on request, for example MySQL on 3306 and RDP on 3389.
- Dynamic or private ports (49152 to 65535): not assigned to anyone. Clients use them for temporary connections. Some operating systems use a slightly different ephemeral range, so do not treat this boundary as a law.
TCP or UDP: which does a service use?
TCP sets up a connection first, then guarantees delivery and order. UDP just sends packets with no handshake and no guarantee. Services that need accuracy (web, mail, file transfer, remote login) use TCP. Services that need speed or send tiny queries (DNS lookups, DHCP, time sync, SNMP) mostly use UDP.
Some use both. DNS normally uses UDP port 53 but switches to TCP for zone transfers and for answers too large for one UDP packet. HTTPS uses TCP 443, and HTTP/3 uses QUIC over UDP 443, so the same number can appear on both protocols.
Common TCP and UDP ports and their services
The table lists the ports you will meet most often in networking exams, firewall work and security assessments. The last column is the part that matters for defence.
| Port | Protocol | Service | What it does and what to watch |
|---|---|---|---|
| 20, 21 | TCP | FTP | File transfer. Credentials and data travel in plain text. Prefer SFTP or FTPS. |
| 22 | TCP | SSH | Encrypted remote login and file copy. Use keys, not passwords, and limit who can reach it. |
| 23 | TCP | Telnet | Plain-text remote login. Replace with SSH wherever you find it. |
| 25 | TCP | SMTP | Mail delivery between servers. Misconfigured servers can be abused as open relays. |
| 53 | UDP and TCP | DNS | Name resolution. Restrict zone transfers; watch for unusually large or frequent queries. |
| 67, 68 | UDP | DHCP | Automatic IP assignment. A rogue DHCP server on a LAN is a known attack. |
| 69 | UDP | TFTP | Very simple file transfer, no authentication. Used for network device boot and configs. |
| 80 | TCP | HTTP | Unencrypted web traffic. Redirect to HTTPS. |
| 88 | TCP and UDP | Kerberos | Authentication in Windows domains. |
| 110 | TCP | POP3 | Mail retrieval, plain text. Use 995 instead. |
| 123 | UDP | NTP | Time sync. Logs and Kerberos both depend on correct time. |
| 135 | TCP | MS-RPC | Windows remote procedure calls. Should not face the internet. |
| 137 to 139 | UDP and TCP | NetBIOS | Legacy Windows name and file sharing services. |
| 143 | TCP | IMAP | Mail access, plain text. Use 993 instead. |
| 161, 162 | UDP | SNMP | Device monitoring (161) and traps (162). Old community strings such as "public" are a common weakness; use SNMPv3. |
| 389 | TCP and UDP | LDAP | Directory queries. Use LDAPS on 636 or StartTLS. |
| 443 | TCP (and UDP for QUIC) | HTTPS | Encrypted web traffic. |
| 445 | TCP | SMB | Windows file sharing. Never expose to the internet; keep patched. |
| 514 | UDP | Syslog | Log shipping, unauthenticated by default. Keep it on a trusted network. |
| 587 | TCP | SMTP submission | Where mail clients send outgoing mail, with authentication and TLS. |
| 993, 995 | TCP | IMAPS, POP3S | Encrypted mail access. |
| 1433 | TCP | Microsoft SQL Server | Database port. Keep it internal. |
| 1521 | TCP | Oracle listener | Oracle database default. |
| 3306 | TCP | MySQL and MariaDB | Database port. Bind to localhost or a private network. |
| 3389 | TCP | RDP | Windows remote desktop. A very common target when exposed; put it behind a VPN or gateway. |
| 5432 | TCP | PostgreSQL | Database port. Keep it internal. |
| 5900 | TCP | VNC | Remote desktop sharing, weak by default. Tunnel it over SSH. |
| 6379 | TCP | Redis | In-memory store, often run without a password. Never expose. |
| 8080 | TCP | HTTP alternate | Common for proxies and app servers. An informal convention, not a rule. |
| 27017 | TCP | MongoDB | Database port. Keep it internal and require authentication. |
Two corrections to a common classroom shortcut: SMTP submission is on 587, not only 25, and port 514 over UDP is syslog while TCP 514 has been used by the old remote shell service. If a question asks for "the" port, read the protocol too.
How to see which ports are open on your own machine
You can inspect your own Linux machine without any scanning tool. The ss command lists sockets that are listening for connections.
ss -tulnp
The flags mean TCP (-t), UDP (-u), listening only (-l), numeric ports (-n) and the owning process (-p). Anything listening on 0.0.0.0 or [::] accepts connections from every network interface. Anything on 127.0.0.1 is reachable only from the machine itself. That difference is the first thing to check when a database "should not be public".
To see what the network sees, use Nmap against a machine you own or a lab VM you built (a Metasploitable VM on a host-only network is the standard choice):
nmap -sV -p 1-1024 192.168.56.101
The -sV flag asks each open port to identify its service and version. This matters because, as noted above, the port number is only a hint. The Nmap reference guide explains the scan types in detail.
Only scan systems you own or have written permission to test. Unauthorised scanning and access can fall under the Information Technology Act, 2000 in India, and a professional engagement always starts with a signed scope document.
Why ports matter in security work
Every open port is a program accepting input from the network. The fewer there are, and the more tightly each is restricted, the less there is to attack. The same list serves both sides.
- Attack surface review: a port scan of your own estate is the quickest way to find a forgotten database or test server that is open to the world.
- Firewall design: you write rules by port and protocol, so you must know what each one is for.
- Detection: a workstation sending large volumes to an unusual high port, or a server suddenly listening on a new port, is worth investigating. Attackers often use non-standard ports, so port number alone proves nothing, but a mismatch between port and traffic is a signal.
- Vulnerability context: many well-known weaknesses are tied to a service on a known port. For example, the SMB flaw patched in Microsoft bulletin MS17-010 affected unpatched systems with port 445 reachable. Patching and not exposing 445 are the fixes, and both are cheap.
How to secure common ports
Start by closing what you do not need, then restrict what you do. A short checklist that works for most small servers:
- List listening services with
ss -tulnpand remove anything you cannot justify. - Default-deny inbound traffic at the host firewall, then allow only what is needed. With UFW that looks like
sudo ufw default deny incomingfollowed bysudo ufw allow 443/tcp. - Limit administrative ports (22, 3389) to a VPN or a short list of source addresses.
- Swap plain-text protocols for encrypted ones: Telnet to SSH, FTP to SFTP, HTTP to HTTPS, POP3 and IMAP to their TLS versions.
- Bind databases (3306, 5432, 6379, 27017) to private addresses and require authentication.
- Keep services patched, and use key-based login plus rate limiting or a tool such as fail2ban on anything internet-facing.
- Log and alert on new listening ports so a change does not go unnoticed.
Changing SSH to a different port reduces log noise from automated scans, but it is not security. Treat it as a minor convenience on top of keys and a firewall, not a replacement.
Common mistakes students make
- Memorising numbers without the protocol. "DNS is 53" is incomplete if you cannot say when it uses TCP.
- Assuming the port number proves the service. Always confirm with version detection.
- Calling a port "closed" when a firewall is silently dropping packets. Scanners report this as "filtered", which is different from closed.
- Forgetting UDP. Scans of UDP are slower and often skipped, which is how an exposed SNMP service gets missed.
Next steps
If you want to practise reading scans and writing firewall rules in a guided lab, the Computer Network course at WebAsha covers protocols and ports from the ground up. For a longer reference list, see Top 20 common network ports and their functions.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0