A second look: services that are exposed by accident far more often than on purpose
How to use this list. Nothing here says a port is open — only
that if the service behind it answers to anyone who can reach the machine, the risk is higher than
the service's age suggests. Check these on machines you own, from the inside, with the tool that
ships with the system:
Plaintext by design. 23 telnet 21 ftp 389 ldap 161 snmp — whatever a password or community string crosses the wire in the clear.
File sharing and remote control. 445 139 137 3389 5900 — these are meant for a local network and should never be reachable from the internet, which is why they are the classic entry point found by scanning.
Databases and caches. 3306 1433 5432 6379 27017 11211 — most of these were designed to sit behind an application, and several have no authentication at all in their default configuration.
Control interfaces. 2375 — an API that can start containers on the host, registered in plain text next to an encrypted sibling. Reaching it is equivalent to running commands on the machine.
A number borrowed by a popular service. 9200 — the registry records this as a mobile web service port, and the same number is widely used by a search engine product that is not in the registry. Rows like this are why the table shows the registered purpose and not a list of products.
What to do instead of guessing. On a machine you control, ask the operating system which
process holds a port (
ss -lntup on Linux,
netstat -abno on Windows), and decide
from the answer. A port being reachable is a configuration question, and the fix is to stop the service,
bind it to the loopback address or put it behind a firewall — in that order.