Ports, Protocols and Services
Ports: The Doors of a Computer
An IP address gets a packet to the right machine. A port gets it to the right program on that machine. Think of an office building: the IP address is the street address, and the port is the room number. A single server can run a website, a mail service and a database at the same time, each listening on a different port.
There are 65,535 TCP ports and 65,535 UDP ports. A port is open when a program is listening, closed when nothing is listening, and filtered when a firewall silently drops the probe.
Every open port is attack surface. A core security habit is: if you do not need a service, turn it off.
Common Ports Every Analyst Should Know
| Port | Protocol | Purpose | Security note |
|---|---|---|---|
| 20/21 | FTP | File transfer | Clear text. Use SFTP instead |
| 22 | SSH | Encrypted remote login | Brute-force target. Use keys |
| 23 | Telnet | Old remote login | Clear text. Disable it |
| 25 | SMTP | Sending email | Abused for spam and spoofing |
| 53 | DNS | Name lookups | Spoofing, tunnelling, amplification |
| 80 | HTTP | Web (unencrypted) | Redirect to HTTPS |
| 110/143 | POP3/IMAP | Reading email | Use the encrypted versions |
| 443 | HTTPS | Web (encrypted) | Expected on any website |
| 445 | SMB | Windows file sharing | WannaCry and ransomware spread |
| 3306 | MySQL | Database | Never expose to the internet |
| 3389 | RDP | Windows remote desktop | Top ransomware entry point |
Well-known ports run from 0 to 1023. Programs you start yourself often use higher ports such as 8080.
Protocols: Secure vs Insecure
A protocol is an agreed set of rules for a conversation. Many older protocols were designed when the network was trusted, so they send everything, including passwords, as plain text.
| Insecure | Secure replacement |
|---|---|
| HTTP | HTTPS (HTTP over TLS) |
| FTP | SFTP or FTPS |
| Telnet | SSH |
| POP3 / IMAP | POP3S / IMAPS |
| SNMP v1/v2 | SNMP v3 |
Anyone on the same network can capture a Telnet or FTP login with a packet sniffer, which you will practise in later lessons.
Scanning: How Attackers and Defenders See Ports
Port scanning is sending probes to a range of ports to see which respond. Defenders scan their own systems to find forgotten services. Attackers scan to find weaknesses. The most popular tool is Nmap:
nmap -sV 10.0.0.5 # detect service versions
nmap -p 1-1024 10.0.0.5 # scan a port range
The service version matters. vsftpd 2.3.4 is not just "FTP": that exact version shipped with a known backdoor, so a scanner result becomes an attack plan.
Legal note: Only scan systems you own or have written permission to test. Unauthorised scanning is treated as unlawful access in many places, including under Nigeria's Cybercrimes Act 2015 and the UK Computer Misuse Act 1990.
A Real-World Pattern
Many breaches worldwide begin with an exposed RDP (3389) or database (3306, 27017) port that someone opened "temporarily" for a vendor and forgot. Fintechs and banks in Lagos, Nairobi and London all face the same issue, which is why security teams run regular external scans and compare the result against an approved list of open ports.
Try It: Port Scanner Simulator
Use the lab on the right. Scan the three fictional servers, read the open ports and services, and answer the question that follows each scan. Ask yourself for every port: does this need to be reachable, and by whom?
Try it yourself
Key Takeaways
- An IP address finds the machine and a port finds the service. Ports can be open, closed or filtered.
- Every open port is attack surface, so disable services you do not need.
- Learn the common ports: 21 FTP, 22 SSH, 23 Telnet, 25 SMTP, 53 DNS, 80 HTTP, 443 HTTPS, 445 SMB, 3306 MySQL and 3389 RDP.
- Use secure protocols (HTTPS, SSH, SFTP) instead of clear-text ones (HTTP, Telnet, FTP).
- Port scanners like Nmap reveal services and versions. Only scan systems you own or are authorised to test.
Quick Quiz
1.What does a port number identify?
2.Which protocol should replace Telnet for remote administration?
3.A scan of your company server shows MySQL (3306) open to the whole internet. What is the best action?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx