Skip to content
Port & Service Database

Port & Service Database

netbobr includes a database of 217 port/service definitions with risk levels and advisory text. These are used for service name autocomplete, port risk scoring, and rule evaluation.

Risk comes from the service configuration, authentication posture, encryption state, and exposure scope - not the port number itself.

Critical Risk Services

PortProtocolServiceAdvisory
23TCPTelnetTransmits all data including credentials in plaintext. Replace with SSH.
102TCPS7comm (Siemens S7)Industrial control protocol with no authentication. Must be isolated.
179TCPBGPRoute hijacking can redirect or blackhole traffic. Restrict to peers.
502TCPModbusNo authentication or encryption. Critical OT protocol requiring strict isolation.
512TCPrexecTrust-based remote execution with plaintext credentials. Replace with SSH.
513TCPrloginTrust-based remote login with no encryption. Replace with SSH.
514TCPrshTrust-based remote shell with no authentication. Replace with SSH.
623UDPIPMI/BMCHardware-level control with known vulnerabilities. Isolate to management network.
2375TCPDocker (unencrypted)Unauthenticated container control. Equivalent to root access on the host.
2379TCPetcd clientKubernetes secrets store. Unauthorized access exposes all cluster secrets.
2380TCPetcd peerCluster consensus protocol. Compromise allows data manipulation.
4505TCPSaltStack PublisherConfiguration management control channel. Compromise controls all minions.
4506TCPSaltStack RequestConfiguration management return channel. Exposes managed infrastructure.
6379TCPRedisDefault config has no authentication. Often contains session data and caches.
6443TCPKubernetes APIFull cluster control. Compromise allows container deployment and secret access.
8200TCPHashiCorp VaultSecrets management system. Unauthorized access exposes all stored secrets.
9200TCPElasticsearch HTTPOften contains sensitive indexed data. Default has no authentication.
9300TCPElasticsearch ClusterInternal cluster protocol. Exposure allows data extraction and manipulation.
10250TCPKubeletNode-level container control. Can execute commands in any pod on the node.
11211TCP/UDPMemcachedNo authentication by design. Can be abused for DDoS amplification.
27017TCPMongoDBDefault config has no authentication. Often contains production data.
27019TCPMongoDB Config ServerSharded cluster metadata. Compromise affects entire cluster routing.
44818TCPEtherNet/IP (CIP)Industrial control protocol. No authentication, direct process manipulation.

High Risk Services

PortProtocolService
20TCPFTP Data
21TCPFTP
42TCP/UDPWINS
49TCPTACACS+
69UDPTFTP
79TCPFinger
111TCP/UDPRPCbind
135TCPRPC/DCOM
137UDPNetBIOS-NS
138UDPNetBIOS-DGM
139TCPNetBIOS-SSN
161UDPSNMP
162UDPSNMP Trap
199TCPSNMP Mux
389TCPLDAP
445TCPSMB
520UDPRIP
523TCPIBM DB2
540TCPUUCP
593TCPHTTP RPC
749TCPKerberos Admin
873TCPRsync
902TCPVMware ESXi
1080TCPSOCKS
1099TCPJava RMI
1433TCPMSSQL
1434UDPMSSQL Browser
1521TCPOracle
1723TCPPPTP
1812UDPRADIUS Auth
1883TCPMQTT
2049TCP/UDPNFS
2082TCPcPanel HTTP
2086TCPWHM HTTP
2376TCPDocker TLS
3268TCPLDAP GC
3283TCPApple Remote Desktop
3306TCPMySQL
3389TCPRDP
4243TCPDocker alt
4369TCPErlang EPMD
4646TCPNomad
5000TCPDocker Registry
5355UDPLLMNR
5432TCPPostgreSQL
5555TCPAndroid ADB
5601TCPKibana
5800TCPVNC HTTP
5900TCPVNC
5984TCPCouchDB
5985TCPWinRM HTTP
7000TCPCassandra
7001TCPWebLogic
7002TCPWebLogic SSL
7474TCPNeo4j HTTP
7687TCPNeo4j Bolt
8006TCPProxmox
8009TCPApache AJP
8042TCPYARN
8086TCPInfluxDB
8123TCPClickHouse
8161TCPActiveMQ
8291TCPMikroTik
8529TCPArangoDB
8834TCPNessus
8888TCPJupyter
9042TCPCassandra CQL
9043TCPWebSphere SSL
9060TCPWebSphere Admin
9090TCPPrometheus
9092TCPKafka
9160TCPCassandra Thrift
10000TCPWebmin
15672TCPRabbitMQ Mgmt
16379TCPRedis Sentinel
25672TCPRabbitMQ Cluster
26257TCPCockroachDB
27018TCPMongoDB shard
28015TCPRethinkDB
28017TCPMongoDB HTTP
47808UDPBACnet
50000TCPJenkins/SAP
50070TCPHDFS NameNode

Medium Risk Services

PortProtocolService
11TCPSystat
19UDPChargen
22TCPSSH
25TCPSMTP
53TCP/UDPDNS
67UDPDHCP Server
70TCPGopher
80TCPHTTP
88TCP/UDPKerberos
110TCPPOP3
113TCPIdent
119TCPNNTP
123UDPNTP
143TCPIMAP
194TCPIRC
220TCPIMAP3
427TCP/UDPSLP
464TCP/UDPKpasswd
500UDPIKE
514UDPSyslog
515TCPLPD
548TCPAFP
554TCPRTSP
631TCPCUPS
636TCPLDAPS
992TCPTelnets
1080TCPSOCKS
1194UDPOpenVPN
1234TCP-
1701UDPL2TP
1813UDPRADIUS Acct
1935TCPRTMP
2083TCPcPanel HTTPS
2087TCPWHM HTTPS
2222TCPSSH alt
3000TCPGrafana
3128TCPSquid
3269TCPLDAPS GC
3478UDPSTUN/TURN
3690TCPSVN
4040TCPSpark UI
4443TCP-
4444TCP-
4500UDPIPsec NAT-T
4848TCPGlassFish
5044TCPBeats
5060TCP/UDPSIP
5222TCPXMPP Client
5269TCPXMPP Server
5353UDPmDNS
5666TCPNRPE
5672TCPAMQP
5938TCPTeamViewer
5986TCPWinRM HTTPS
6660-6669TCPIRC alt
8000TCPHTTP-alt
8008TCPHTTP-alt
8080TCPHTTP-alt
8081TCPHTTP-alt
8082TCPHTTP-alt
8083TCPHTTP-alt
8088TCPHTTP-alt
8181TCPHTTP-alt
8444TCPHTTPS-alt
8554TCPRTSP alt
8649TCPGanglia
8761TCPEureka
8880TCPHTTP-alt
9000TCPHTTP-alt
9100TCPJetDirect
9418TCPGit
9443TCPHTTPS-alt
9600TCPLogstash
9999TCPHTTP-alt
31337TCP-
32400TCPPlex

Low Risk Services

PortProtocolService
7TCP/UDPEcho
9TCP/UDPDiscard
13TCPDaytime
17TCPQOTD
37TCP/UDPTime
43TCPWHOIS
68UDPDHCP Client
443TCPHTTPS
465TCPSMTPS
563TCPNNTPS
587TCPSMTP Submission
853TCPDNS over TLS
989TCPFTPS Data
990TCPFTPS Control
993TCPIMAPS
995TCPPOP3S
5061TCPSIP/TLS
5671TCPAMQP/TLS
6514TCPSyslog/TLS
6697TCPIRC/TLS
8443TCPHTTPS-alt
8883TCPMQTT/TLS
25565TCPMinecraft
8333TCPBitcoin
51820UDPWireGuard