Skip to main content
QUIETLYTIC
Networking

Common Ports Lookup

Look up what normally listens on a TCP or UDP port, and why it matters if it is exposed.

Local · nothing leaves this browser 60 ports indexed
Esc Clear
Service, transport and exposure

Enter a port number on the left.

How it works

A port number is a label on a door, not a verdict about what is behind it. This page tells you what conventionally listens on one and what is worth knowing if it turns up reachable — which are two different facts, kept apart on purpose.

An open port is not a vulnerability

Worth being precise about, because findings get written from this distinction. Whether a port should be open depends on what answers it and who can reach it. What is reportable is an unauthenticated or obsolete service reachable from an untrusted network — a database with no password, Telnet on an internet-facing host, a BMC on 623 that is full hardware control to anyone who finds it. The exposure rating here speaks to that reachability question. It never claims the service itself is flawed.

Three ranges, and only two are assigned

0–1023 are system ports, assigned by IANA; binding one traditionally needs root on Unix-like systems. 1024–49151 are registered on request. 49152–65535 are ephemeral and never assigned to anything — the operating system hands them out as the source port of outbound connections and reuses them constantly. A connection from port 51423 tells you only that some client opened a socket.

Some entries are here for what they mean, not what they are

Port 4444 has no meaningful assignment. It is listed because it is Metasploit's default listener, so it runs through a great many public exploit write-ups and through the traffic of everyone who followed one without changing the default. That is a fact about what you will see in a log, and it is labelled as such rather than dressed up as an assignment.

Example

445 is SMB over TCP — the port EternalBlue and WannaCry spread over, and one that should never be reachable from the internet. 3389 is RDP, the most common initial-access route for ransomware. Search amplification instead of a number and you get the UDP services abused for reflected DDoS: DNS, NTP, memcached, the SQL Server browser.

Frequently asked questions

Does a port being open mean it is a vulnerability?

No, and the distinction matters when you are writing a finding up. A port is a door; whether it should be open depends on what is behind it and who can reach it. What is reportable is an unauthenticated or legacy service reachable from an untrusted network — an exposed database with no password, or Telnet on an internet-facing host. The exposure rating here is about that reachability question, not a claim that the service is flawed.

Why are ports above 49151 not assigned to anything?

Because that range is deliberately never assigned. Those are ephemeral ports, which an operating system hands out as the source port for outbound connections and reuses constantly. A connection from port 51423 tells you only that some client opened a socket.

Why is port 4444 listed when it has no real assignment?

Because recognising it is useful even though the assignment is not. It is the default listener port in Metasploit, so it appears throughout public exploit write-ups and in traffic from anyone who followed one without changing the default. That is a fact about what you will see in logs, not an assignment.

Related tools

From the intelligence desk