---
title: "How does Cynergy calculate risk?"
canonical: "https://kb.cynergy.app/space/GS/902824041/How%20does%20Cynergy%20calculate%20risk%3F"
format: markdown
---
![image](media://fd61dd28-b6aa-4a47-ae24-df221dfe393a)


**Cynergy Exposure Scoring: The higher the better.**

|  |  |  |
| --- | --- | --- |
| **A** | 95-100 | The organization's external exposure is contained with relevant security controls.<br>Residual exposure is limited to internal threat actors, advanced social engineering attacks and potential sophisticated and persistent attackers (nation states) deploying complex attacks. |
| **B** | 81-94 | The organization’s external exposure is vulnerable due to misconfigurations or weaknesses in deployed security controls. A reasonably motivated and competent attacker could readily gain external access by exploiting exposed weaknesses.<br>Further residual exposure exists from internal threat actors, advanced social engineering attacks and potential sophisticated and persistent attackers (nation states) deploying complex attacks. |
| **C** | 71-80 | The organization’s external exposure is significantly vulnerable due to inefficient controls across many digital assets. A moderately motivated and competent attacker could readily gain external access by exploiting exposed weaknesses.<br>Further residual exposure exists from internal threat actors, advanced social engineering attacks and potential sophisticated and persistent attackers (nation states) deploying complex attacks. |
| **D** | 61-70 | The organization’s external exposure is extremely vulnerable due to inefficient controls across a majority of digital assets. A minimally motivated and competent attacker could readily gain external access by exploiting exposed vulnerabilities.<br>Further residual exposure exists from internal threat actors, advanced social engineering attacks and potential sophisticated and persistent attackers (nation states) deploying complex attacks. |
| **E** | 51-60 | The organization’s external exposure is critically vulnerable due to inefficient controls across its digital estate. A basic level attacker could readily gain external access by exploiting exposed vulnerabilities. It is possible that these vulnerabilities have already been exploited.<br>Further residual exposure exists from internal threat actors, advanced social engineering attacks and potential sophisticated and persistent attackers (nation states) deploying complex attacks. |
| **F** | 0-50 | The organization is critically and extremely exposed, due to absence of basic security controls across its digital estate. An imminent attack is likely, if not already exploited, by basic automated attackers.<br>Further residual exposure exists from internal threat actors, advanced social engineering attacks and potential sophisticated and persistent attackers (nation states) deploying complex attacks. |


<u>**Abstract**</u>

Cynergy is a cybersecurity automated remediation platform for internet-facing cybersecurity risks. As part of our approach to remediate the identified risks, Cynergy has defined a state-of-the-art process for defining a risk score for assets and domains. Organizations all over the world are using Cynergy to act on the identified risks by Cynergy. Cynergy’s unique differentiation is in its approach to identifying the organization’s exposure versus most security rating providers which are looking at the organization’s security performance as key risk criteria. 


<u>**General introduction - Why a Risk Score is needed?**</u>

As part of the digital transformation, organizations are moving their physical assets to the internet. Applications and Infrastructure are rapidly moving to a cloud infrastructure. most of the On-premises IT is rapidly shifting to the cloud and most of the product development processes are shifting to cloud-based pipelines. The organizations are not operating in a vacuum. Most of them are managing an environment that includes multiple 3rd parties, and 4th parties. Services, SaaS platforms, and analytic platforms.

Managing the organization's risk in such a complex environment becomes a major challenge for organizations since the internal and external aspects of the organization’s digital environment

- **Validated Risk Scoring** is done by active validation of the risk based on the exploitation of the identified vulnerabilities, to provide a risk score that is based on a high percentage of attack surface coverage and optimized with a low amount of false positives.
  

**Risk model validation questions:**

**Q:** If you have two different companies with the same size and same vulnerabilities, How can Cynergy identify the relevant risk score?

**A:** Without additional information, it is impossible to determine the risk.

**Q:** If you have two different companies with the same size and same vulnerabilities one is a Healthcare organization the other is Fintech, How can Cynergy identify the relevant risk score?

**A:** Each vulnerability is assessed per its business impact, once there are inputs of company geolocation and business vertical, its assets are analyzed for their priority, the type of data that is available from the asset, and its interconnectivity. 

**Example:** Healthcare and Fintech organizations from the USA that have the same SQL injection vulnerability. based on the trend of attacks it can be determined that Healthcare organizations are being attacked at a higher frequency.  The fines which Healthcare organizations are getting due to HIPPA regulation are higher than the fines Fintech companies are getting for a record loss. While the Churn and reputational loss of a Fintech company are higher. While to cost of recovery is much higher for Healthcare companies. Once all elements are standardized and calculated, it can be determined that Healthcare risk is higher once having the same vulnerabilities. 

Not like other cybersecurity risk score providers who measure the cybersecurity performance of the organization. Cynergy is looking at the exposure risk. The exposure risk is based on sources of data collected from a reconnaissance covering the most predominant attack vectors, which are leveraged by attackers.  
Cloud, Applications, Data-leak, Infrastructure, Network, Technologies, SaaS and 3rd parties, Privacy and Employee risks.   
Each identified organization asset is being inventoried and passes contextualization and threat modeling to assess the impact of a singular asset on the overall security risk based on STAMP (System-Theoretic  
Accident Model and Process), which searches for individual component failures by identifying missing requirements, configurations, design mistakes problematic interactions between components, and human errors. shifting focus away from pinpointing problems one-by-one and instead dynamically identifying dysfunctional interactions and behaviors within the system as a whole.

To correctly threat model exposure, Cynergy uses ML to contextualize and classify the exposure, to define what is its criticality to the organization’s business continuity.  
Resulting in an accurate threat model per each identified asset in the organization.  
The weights of the risk from each vector are being standardized based on Benford's law, to assess the correctness of the ML models over time.  
The exposure risk is being calculated based on quantitive threat modeling of the exposed, Web and Mobile applications UI, APIs, Javascript external communication and the data transfer to 3rd parties, Features, Data, Cloud instances and buckets, Infrastructure assets, employee and organization data leakage, DNS and SMTP misconfigurations.  
The risk weights between the discovered assets are continuously checked via the ANOVA statistic model for consistency.  
And the overall score is being standardized using the MANOVA statistic model.


**A risk score is a dynamic object which is re-calculated every time that a new scan is done.**

The base Risk score is A which is equivalent to a 100 score

Every asset risk score is calculated separately 

![image](media://c349dfc3-1a84-48b9-9f26-0a789117ff03)

There are 2 levels of Risk Scoring

1. Passive
2. Active - validated

**Passive**

1. Web Applications
  1. Vulnerable Technologies
    1. Has CVE
      1. Based on CVSS3 score if there is no such score then based on CVSS2
      2. Take into consideration the EPSS score of a CVE
2. Mobile Applications
  1. Identified applications not in the official marketplace
  2. Hacked Applications for download
3. Infrastructure
  1. Hijackable Subdomains
  2. Open Ports
  3. DNS Misconfigurations
    1. Zone Transfer
    2. Open DNS Resolver
  4. SMTP Misconfigurations
    1. SPF
    2. DKIM
    3. Open Relay
4. Cloud
  1. Exposed Instances
  2. Exposed cloud storage
5. Employees
  1. Leaked Credentials validated against main SaaS providers - Last 3 months
  2. Leaked Credentials validated against main SaaS providers  - 3 - 6 months
6. Data
  1. Leaked Data
    1. Pastesites - e.g Pastebin
    2. GitHub


# <u>**Risk Calculation**</u>

The purpose here is to provide the scoring calculation mechanism per the risk score, each high-level category is getting its appropriate weight, while internal categories have their own weight as part of the general category.  

### **Process: **

![image](media://e1f4c514-c13d-4d53-9ced-efa785766864)


## <u>**Infrastructure 40%**</u>

**Number of Subdomains** - adding to the weight of score.

**Open Ports - Top 50 ports - 15% of score**

**Calculation:**

1 host - port  21 open == 0.15(Total Score)  * 0.7( port 21 open) == 0.105 

10 hosts -  2 assets  with open ports 21 22 23 (0.7*0.8*0.2)  = ((1*8 + 0.112*2)/10)*0.15  == 0.12336

There are several open ports that will fail the tests - If any of the following ports will be found open that the full test will fail and there will a reduction of 15% from the score. 

3389, 3306, 9200, 1433, 5432, 1521

<details>
<summary>Ports and Score</summary>

| **Port Number** | **Protocol** | **Name** | **Description ** | **Risk Waigh** | **Active Tests** |
| --- | --- | --- | --- | --- | --- |
| 21 | tcp | FTP | File Transfer Protocol [[RFC 959](http://tools.ietf.org/html/rfc959)] - some network devices may be listening on this port, such as NAT routers for remote access/private cloud storage and network attached multi-function printers (scan to ftp feature).<br>Asus RT routers may open an internet accessible FTP server for USB-attached storage, configurable in administration panel under "USB Application > Servers Center > FTP Share"<br>Trojan horses/backdoors that also use this port: 7tp trojan, MBT, Back Construction, Blade Runner, Cattivik FTP Server, CC Invader, Dark FTP, Doly Trojan, Fore, Invisible FTP, Juggernaut 42, Larva, MotIv FTP, Nerte 7.8.1, Net Administrator, Ramen, Senna Spy FTP server, The Flu, Traitor 21, WebEx, WinCrash, [W32.Mytob.AE](http://W32.Mytob.AE)@mm [[Symantec-2005-040915-5504-99](https://www.symantec.com/security-center/writeup/2005-040915-5504-99)], W32.Sober.N@mm [[Symantec-2005-041910-4132-99](https://www.symantec.com/security-center/writeup/2005-041910-4132-99)], [W32.Bobax.AF](http://W32.Bobax.AF)@mm [[Symantec-2005-081611-4121-99](https://www.symantec.com/security-center/writeup/2005-081611-4121-99)] - a mass-mailing worm that opens a backdoor and lowers security settings on the compromised computer. It exploits the MS Plug and Play Buffer Overflow vulnerability (MS Security Bulletin [[MS05-039](http://technet.microsoft.com/en-us/security/bulletin/MS05-039)]) on port 21/tcp., and by sending copies of itself to gathered email addresses. Also opens a backdoor on a random tcp port and/or port 80/udp.<br>W32.Loxbot.C [[Symantec-2006-010515-3159-99](https://www.symantec.com/security-center/writeup/2006-010515-3159-99)] (2006-01-05)<br>FTP proxy server for Novell BorderManager 3.6 SP 1a allows remote attackers to cause a denial of service (network connectivity loss) via a connection to port 21 with a large amount of random data.  
References: [[CVE-2002-0779](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0779)]<br>TURCK BL20 / BL67 could allow a remote attacker to bypass security restrictions, caused by the use of hardcoded credentials for the FTP service. An attacker could exploit this vulnerability using TCP port 21 to gain administrative access to the device.  
References: [[CVE-2012-4697](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4697)], [[XFDB-84351](https://exchange.xforce.ibmcloud.com/vulnerabilities/84351)]<br>The FTP service in QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, has hardcoded credentials, which makes it easier for remote attackers to obtain access via a session on TCP port 21.  
References: [[CVE-2015-7261](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7261)]<br>The FTP service on Janitza UMG 508, 509, 511, 604, and 605 devices has a default password, which makes it easier for remote attackers to read or write to files via a session on TCP port 21.  
References: [[CVE-2015-3968](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3968)]<br>A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 21/tcp to access or alter historical measurement data stored on the device.  
References: [[CVE-2017-6872](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6872)], [[BID-99473](http://www.securityfocus.com/bid/99473)]<br>A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The two FTP services (default ports 21/tcp and 5411/tcp) of the SiNVR 3 Video Server contain a path traversal vulnerability that could allow an authenticated remote attacker to access and download arbitrary files from the server, if the FTP services are enabled.  
References: [[CVE-2019-19296](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19296)] | 0.7 | - Anonymous Login |
|  |  | SSH | Secure Shell - most common use is command line access, secure replacement of Telnet. Could also be used as an encrypted tunnel for secure communication of virtually any service [RFC 4251], [RFC 4960]<br>freeSSHd 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a SSH2_MSG_NEWKEYS packet to TCP port 22, which triggers a NULL pointer dereference.  
References: [CVE-2008-0852] [BID-27845] [SECUNIA-29002]<br>The SSH service on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of service (device reset) or possibly execute arbitrary code by sending many packets to TCP port 22.  
References: [CVE-2013-3594], [XFDB-90595], [BID-65070]<br>RUCKUS could allow a remote attacker to bypass security restrictions. An unauthenticated remote attacker with network access to port 22 can tunnel random TCP traffic to other hosts on the network via Ruckus devices. A remote attacker could exploit this vulnerability to bypass security restrictions and gain unauthorized access to the vulnerable application.  
References: [XFDB-84626]<br>360 Systems contains a default hard-coded password in the image server series. By logging into the device via TCP port 22, a remote attacker could gain root privileges on the system to modify or upload video to play immediately and affect the emergency broadcast system in the United States.  
References: [XFDB-82650], [BID-58338], [CVE-2012-4702]<br>Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.  
References: [CVE-2016-8209], [XFDB-125665]<br>A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR 5000 Series, ASR 5500 Series, ASR 5700 Series devices, and Cisco Virtualized Packet Core could allow an authenticated, remote attacker to gain unrestricted, root shell access. The vulnerability is due to missing input validation of parameters passed during SSH or SFTP login. An attacker could exploit this vulnerability by providing crafted user input to the SSH or SFTP command-line interface (CLI) during SSH or SFTP login. An exploit could allow an authenticated attacker to gain root privileges access on the router. Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulnerability can be triggered via both IPv4 and IPv6 traffic. An established TCP connection toward port 22, the SSH default port, is needed to perform the attack. The attacker must have valid credentials to login to the system via SSH or SFTP. The following products have been confirmed to be vulnerable: Cisco ASR 5000/5500/5700 Series devices running StarOS after 17.7.0 and prior to 18.7.4, 19.5, and 20.2.3 with SSH configured are vulnerable. Cisco Virtualized Packet Core - Single Instance (VPC-SI) and Distributed Instance (VPC-DI) devices running StarOS prior to N4.2.7 (19.3.v7) and N4.7 (20.2.v0) with SSH configured are vulnerable. Cisco Bug IDs: CSCva65853.  
References: [CVE-2017-3819], [BID-96913]<br>Including port 22 in the list of allowed FTP ports in Networking in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially enumerate internal host services via a crafted HTML page.  
References: [CVE-2018-6082], [BID-103297]<br>A vulnerability has been identified in ROX II (All versions < V2.12.1). An authenticated attacker with a high-privileged user account access via SSH could circumvent restrictions in place and execute arbitrary operating system commands. Successful exploitation requires that the attacker has network access to the SSH interface in on port 22/tcp. The attacker must be authenticated to exploit the vulnerability. The vulnerability could allow an attacker to execute arbitrary code on the device.  
References: [CVE-2018-13802], [BID-105545]<br>A vulnerability has been identified in ROX II (All versions < V2.12.1). An attacker with network access to port 22/tcp and valid low-privileged user credentials for the target device could perform a privilege escalation and gain root privileges. Successful exploitation requires user privileges of a low-privileged user but no user interaction. The vulnerability could allow an attacker to compromise confidentiality, integrity and availability of the system.  
References: [CVE-2018-13801], [BID-105545]<br>The Auto-Maskin DCU 210E firmware contains an undocumented Dropbear SSH server, v2015.55, configured to listen on Port 22 while the DCU is running. The Dropbear server is configured with a hard-coded user name and password combination of root / amroot. The server is configured to use password only authentication not cryptographic keys, however the firmware image contains an RSA host-key for the server. An attacker can exploit this vulnerability to gain root access to the Angstrom Linux operating system and modify any binaries or configuration files in the firmware. Affected releases are Auto-Maskin DCU-210E RP-210E: Versions prior to 3.7 on ARMv7.  
References: [CVE-2018-5399]<br>An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless address autoconfiguration) by default, which makes it easier for remote attackers to obtain access by guessing 24 bits of the MAC address and attempting a root login. This can be exploited in conjunction with CVE-2017-17878.  
References: [CVE-2017-17877]<br>A vulnerability has been identified in SCALANCE SC-600 (V2.0). An authenticated attacker with access to port 22/tcp as well as physical access to an affected device may trigger the device to allow execution of arbitrary commands. The security vulnerability could be exploited by an authenticated attacker with physical access to the affected device. No user interaction is required to exploit this vulnerability. The vulnerability impacts the confidentiality, integrity and availability of the affected device.  
References: [CVE-2019-10928]<br>Some trojans also use this port: InCommand, Shaft, Skun | 0.8 | - Credential Access |
| 23 |  | Telnet | Telnet is one of the oldest Internet protocols and the most popular program for remote access to Unix machines. It has numerous security vulnerabilities [RFC 854]<br>Trojans that also use this port: Prosiak, Wingate, ADM worm, Aphex's Remote Packet Sniffer , AutoSpY, ButtMan, Fire HacKer, My Very Own trojan, Pest, RTB 666, Tiny Telnet Server - TTS, Truva Atl, Backdoor.Delf variants [Symantec-2003-050207-0707-99], Backdoor.Dagonit [Symantec-2005-092616-0858-99] (2005.09.26)<br>Stack-based buffer overflow in RabidHamster R2/Extreme 1.65 and earlier allows remote authenticated users to execute arbitrary code via a long string to TCP port 23.  
References: [CVE-2012-1222], [BID-52061]<br>The Emerson DeltaV SE3006 through 11.3.1, DeltaV VE3005 through 10.3.1 and 11.x through 11.3.1, and DeltaV VE3006 through 10.3.1 and 11.x through 11.3.1 allow remote attackers to cause a denial of service (device restart) via a crafted packet on (1) TCP port 23, (2) UDP port 161, or (3) TCP port 513.  
References: [CVE-2012-4703]<br>Buffer overflow in the Remote command server (Rcmd.bat) in IpTools (aka Tiny TCP/IP server) 0.1.4 allows remote attackers to cause a denial of service (crash) via a long string to TCP port 23.  
References: [CVE-2012-5345]<br>Hospira Lifecare PCA infusion pump running "SW ver 412" does not require authentication for Telnet sessions, which allows remote attackers to gain root privileges via TCP port 23.  
References: [CVE-2015-3459]<br>Zhuhai RaySharp firmware has a hardcoded root password, which makes it easier for remote attackers to obtain access via a session on TCP port 23 or 9000.  
References [CVE-2015-8286]<br>Hughes satellite modems contains default telnet service (port 23) account credentials. A remote attacker could exploit this vulnerability to gain administrative access on affected devices.  
References: [CVE-2016-9495], [XFDB-122123]<br>An issue was discovered in Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 firmware. It is configured to provide TELNET remote access (without a password) that pops a shell as root. If an attacker can connect to port 23 on the device, he can completely compromise it.  
References: [CVE-2018-12072]<br>Telestar Digital GmbH Imperial and Dabman Series I and D could allow a remote attacker to gain elevated privileges on the system, caused by the use of weak passwords with hardcoded credentials in an undocumented Telnet service (Telnetd) that connects to Port 23. A remote attacker could exploit this vulnerability to gain root access to the gadgets' embedded Linux BusyBox operating system.  
References: [CVE-2019-13473], [XFDB-166724]<br>Multiple C-Data OLT devices are vulnerable to a denial of service, caused by a shawarma attack. By sending random bytes to the telnet server on port 23, a remote attacker could exploit this vulnerability to cause the device to reboot.  
References: [CVE-2020-29057], [XFDB-192290]<br>An issue was discovered on FiberHome HG6245D devices through RP2613. The telnet daemon on port 23/tcp can be abused with the gpon/gpon credentials.  
References: [CVE-2021-27165]<br>TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-16734. To connect, the telnet service is used on port 23 with the default password of 059AnkJ for the root account. The user can then download the filesystem through preinstalled BusyBox utilities (e.g., tar and nc).  
References: [CVE-2021-37555] | 0.2 | - Establish Connection |
| 25 | tcp | SMTP | SMTP (Simple Mail Transfer Protocol). Many worms contain their own SMTP engine and use it to propagate by mass-mailing the payload, often also spoofing the "From: ..." field in emails. If you are not running a mail server that you're aware of, there is a possibility your system is infected.<br>Integer overflow in Apple Safari [[CVE-2010-1099](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1099)], Arora [[CVE-2010-1100](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1100)], Alexander Clauss iCab [[CVE-2010-1101](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1101)], OmniWeb [[CVE-2010-1102](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1102)], Stainless [[CVE-2010-1103](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1103)] allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data type, as demonstrated by a value of 65561 for TCP port 25.<br>List of some trojan horses/backdoors that use this port: Ajan, Antigen, Barok, Email Password Sender - EPS, EPS II, Gip, Gris, Happy99, Hpteam mail, Hybris, I love you, Kuang2, Magic Horse, MBT (Mail Bombing Trojan), Moscow Email trojan, Naebi, NewApt worm, ProMail trojan, Shtirlitz, Stealth, Tapiras, Terminator, WinPC, WinSpy, Aji, Email Worms, Haebu Coceda, Loveletter, Neabi, Shtrilitz.  
W32.Sober.I@mm [[Symantec-2004-111900-1451-99](https://www.symantec.com/security-center/writeup/2004-111900-1451-99)] (2004.11.19) - mass-mailing worm that uses its own SMTP engine. Affects all current Windows versions. Checks network connectivity by contacting a NTP server on port 37/tcp.  
Trojan.Mitglieder.R [[Symantec-2005-070117-2559-99](https://www.symantec.com/security-center/writeup/2005-070117-2559-99)] (2005.07.01) - trojan with backdoor capabilities. It runs a SOCKS4 proxy server and periodically contacts websites with information about the compromised computer. Attempts to open a back door on port 9040/tcp. Might also initiate a SMTP spam relay server on port 25/tcp.  
[W32.Beagle.CX](http://W32.Beagle.CX)@mm [[Symantec-2005-121511-1751-99](https://www.symantec.com/security-center/writeup/2005-121511-1751-99)] (2005.12.15) - mass-mailing worm that uses its own SMTP engine to spread Trojan.Lodear.E [[Symantec-2005-110111-3344-99](https://www.symantec.com/security-center/writeup/2005-110111-3344-99)]. Also opens a backdoor on port 80/tcp and lowers security settings on the compromised computer.  
Backdoor.Rustock [[Symantec-2006-060111-5747-99](https://www.symantec.com/security-center/writeup/2006-060111-5747-99)] (2006.06.01) - backdoor program that allows the compromised computer to be used as a proxy, uses rootkit techniques to hide its files and registry entries.<br>NJStar Communicator is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the MiniSMTP server when processing packets. By sending a specially-crafted request to TCP port 25, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.  
References: [[CVE-2011-4040](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4040)], [[XFDB-71086](https://exchange.xforce.ibmcloud.com/vulnerabilities/71086)], [[BID-50452](http://www.securityfocus.com/bid/50452)]<br>Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use cleartext SMTP on port 25 in some cases where encryption on port 465 was intended.  
References: [[CVE-2021-43270](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43270)] | 0.3 | - Open Relay |
| 26 | tcp | RSFTP | Port used by RSFTP - a simple FTP-like protocol.<br>Sometimes also used as an alternate to port 25 SMTP (Simple Mail Transfer Protocol). | 0.3 |  |
| 53 | tcp,udp | DNS | DNS (Domain Name Service) used for domain name resolution. There are some attacks that target vulnerabilities within DNS servers.<br>Cisco Webex Teams services uses these ports:  
443,444,5004 TCP  
53, 123, 5004, 33434-33598 UDP (SIP calls)<br>Xbox 360 (Live) ports: 3074 TCP/UDP, 53 TCP/UDP, 80 TCP, 88 UDP  
Xbox One (Live) ports: 3074 TCP/UDP, 53 TCP/UDP, 80 TCP, 88 UDP, 500 UDP, 3544 UDP, 4500 UDP<br>Apple MacDNS, FaceTime also use this port.<br>Some trojans also use this port: ADM worm, Bonk (DoS) trojan, li0n, MscanWorm, MuSka52, Trojan.Esteems.C [Symantec-2005-051212-1727-99] (2005.05.12), W32.Spybot.ABDO [Symantec-2005-121014-3510-99] (2005.12.10).<br>W32.Dasher.B [Symantec-2005-121610-5037-99] (2005.12.16) - a worm that exploits the MS Distributed Transaction Coordinator Remote exploit (MS Security Bulletin [MS05-051]).  
Listens for remote commands on port 53/tcp. Connects to an FTP server on port 21211/tcp. Scans for systems vulnerable to the [MS05-051] exploit on port 1025/tcp.<br>Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the firewall filters via packets with a source port of 53.  
References: [CVE-2003-1491] [BID-7436]<br>Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attackers to execute arbitrary code by sending a crafted packet to port 53/udp, a different issue than [CVE-2007-1465].  
References: [CVE-2007-1866] [SECUNIA-24688]<br>Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote attackers to cause a denial of service (device restart and loss of configuration) by connecting to TCP port 53, then closing the connection.  
References: [CVE-2009-1152] [BID-34220]<br>Cisco IOS is vulnerable to a denial of service, caused by an error in NAT of DNS. By sending specially-crafted DNS packets to TCP port 53, a remote attacker could exploit this vulnerability to cause the device to reload.  
References: [CVE-2013-5479], [XFDB-87455]<br>haneWIN DNS Server is vulnerable to a denial of service attack. A remote attacker could send a large amount of data to port 53 and cause the server to crash.  
References: [XFDB-90583], [BID-65024], [EDB-31014]<br>named in ISC BIND 9.x (before 9.9.7-P2 and 9.10.x before 9.10.2.-P3) allows remote attackers to cause denial of service (DoS) via TKEY queries. A constructed packet can use this vulnerability to trigger a REQUIRE assertion failure, causing the BIND daemon to exit. Both recursive and authoritative servers are vulnerable. The exploit occurs early in the packet handling, before checks enforcing ACLs or configuration options that limit/deny service.  
See: [CVE-2015-5477]<br>Tftpd32 is vulnerable to a denial of service, caused by an error when processing requests. If the DNS server is enabled, a remote attacker could send a specially-crafted request to UDP port 53 to cause the server to crash.  
References: [XFDB-75884] [BID-53704] [SECUNIA-49301]<br>TP-Link TL-WR886N 7.0 1.1.0 devices allow remote attackers to cause a denial of service (Tlb Load Exception) via crafted DNS packets to port 53/udp.  
References: [CVE-2018-19528]<br>MikroTik RouterBOARD v6.39.2 and v6.40.5 allows an unauthenticated remote attacker to cause a denial of service by connecting to TCP port 53 and sending data that begins with many '\0' characters, possibly related to DNS.  
References: [CVE-2017-17537], [EDB-43200] | 0.7 |  |
| 80<br>- clickable [http://website](http://website) | tcp | HTTP | Hyper Text Transfer Protocol (HTTP) - port used for web traffic.<br>Some broadband routers run a web server on port 80 or 8080 for remote management. WAN Administration can (and should, in most cases) be disabled using the Web Admin interface.<br>AnyDesk remote desktop software uses TCP ports 80, 443, 6568, 7070 (direct line connection)<br>If you're not running web services, keep in mind that a number of trojans/worms/backdoors propagate via TCP port 80 (HTTP):  
Code Red, Nimda, 711 trojan (Seven Eleven), AckCmd, Back End, Back Orifice 2000 Plug-Ins, Cafeini, CGI Backdoor, Executor, God Message, God Message Creator, Hooker, IISworm, MTX, NCX, Nerte 7.8.1, Reverse WWW Tunnel Backdoor, RingZero, Seeker, WAN Remote, Web Server CT, WebDownloader  
Trojan.Webus.C [[Symantec-2004-101212-0903-99](https://www.symantec.com/security-center/writeup/2004-101212-0903-99)]  
[W32.Beagle.AO](http://W32.Beagle.AO)@mm [[Symantec-2004-080911-3251-99](https://www.symantec.com/security-center/writeup/2004-080911-3251-99)] - mass-mailing worm with backdoor functionality. Uses its own SMTP engine, discovered 08.09.2004. Opens port 80 tcp & udp.  
Mydoom.B [[Symantec-2004-012816-3647-99](https://www.symantec.com/security-center/writeup/2004-012816-3647-99)] (2004.01.28) - mass-mailing worm that opens a backdoor into the system. The backdoor makes use of TCP ports 80, 1080, 3128, 8080, and 10080.  
Backdoor.Ranky.S [[Symantec-2005-013015-4228-99](https://www.symantec.com/security-center/writeup/2005-013015-4228-99)] (2005.01.30) - runs proxy on port 80.  
W32.Crowt.A@mm [[Symantec-2005-012310-2158-99](https://www.symantec.com/security-center/writeup/2005-012310-2158-99)] (2005.01.23) - mass mailing worm, opens a backdoor, logs keystrokes. Uses ports 80 and 137.  
Backdoor.Darkmoon.B [[Symantec-2005-102115-3914-99](https://www.symantec.com/security-center/writeup/2005-102115-3914-99)] (2005.10.21) - a backdoor trojan with keylogger capabilities. Opens a backdoor and listens for remote commands on port 80/tcp.  
[W32.Beagle.CX](http://W32.Beagle.CX)@mm [[Symantec-2005-121511-1751-99](https://www.symantec.com/security-center/writeup/2005-121511-1751-99)] (2005.12.16) - mass-mailing worm that uses its own SMTP engine to spread Trojan.Lodear.E [[Symantec-2005-121516-1510-99](https://www.symantec.com/security-center/writeup/2005-121516-1510-99)]. Also opens a backdoor on port 80/tcp and lowers security settings on the compromised computer.  
Trojan.Lodear.F [[Symantec-2005-121513-5818-99](https://www.symantec.com/security-center/writeup/2005-121513-5818-99)] (2005.12.18) - trojan that attempts to download remote files.  
W32.Feebs [[Symantec-2006-013122-5631-99](https://www.symantec.com/security-center/writeup/2006-013122-5631-99)] (2006.01.07)<br>Xbox 360 (LIVE) ports: 3074 TCP/UDP, 53 TCP/UDP, 80 TCP, 88 UDP  
Xbox One (LIVE) ports: 3074 TCP/UDP, 53 TCP/UDP, 80 TCP, 88 UDP, 500 UDP, 3544 UDP, 4500 UDP<br>Some Apple applications also use port 80 (TCP): MobileMe, Sherlock, QuickTime Installer, iTunes Store and Radio, Software Update, RAID Admin, Backup, iCal calendar publishing, iWeb, MobileMe Web Gallery Publishing, WebDAV (iDisk), Final Cut Server.<br>Siemens SIPROTEC 4 and SIPROTEC Compact is vulnerable to a denial of service, caused by an error in the EN100 Ethernet module. By sending specially-crafted HTTP packets to TCP port 80, a remote attacker could exploit this vulnerability to cause the device to go into defect mode.  
References: [[CVE-2016-7113](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7113)] [[XFDB-116647](https://exchange.xforce.ibmcloud.com/vulnerabilities/116647)]<br>A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the web server by sending specially crafted network packets to port 443/TCP or port 80/TCP.  
References: [[CVE-2017-6869](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6869)], [[BID-99343](http://www.securityfocus.com/bid/99343)] | 1 |  |
| 81<br>- clickable [http://website](http://website) | tcp | http | Hyper Text Transfer Protocol (HTTP) - ports used for web traffic. See also TCP ports 80, 8080, 8081.<br>Some common uses for port 81/tcp include web administration (cobalt cube), web proxy servers, McAfee Framework Service, TigerVPN (servers speed check), etc.<br>If you're not running web services on this port, keep in mind it is also used by some trojans:  
Backdoor.Asylum [[Symantec-2000-121815-0609-99](https://www.symantec.com/security-center/writeup/2000-121815-0609-99)] (2000.05.02) - remote access trojan, uses ports 81, 2343, 23432 by default.  
[W32.Beagle.AR](http://W32.Beagle.AR)@mm [[Symantec-2004-092811-5825-99](https://www.symantec.com/security-center/writeup/2004-092811-5825-99)] (2004.09.28) - port 81.<br>Stack-based buffer overflow in the RespondeHTTPPendiente function in the HTTP server for SUMUS 0.2.2 allows remote attackers to execute arbitrary code via a large packet sent to TCP port 81.  
References: [[CVE-2005-1110](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1110)]<br>RemoConChubo trojan and Blue Iris also use this port. | 1 |  |
| 110 | tcp | POP3 | POP3 (Post Office Protocol - Version 3)<br>Security Concerns: Re-usable cleartext password, no auditing of connections & attempts thus subject to grinding. Some POP3 server versions have had buffer overflow problems. CERT Advisories: CA-97.09<br>ADM, ProMail trojans also use port 110 (TCP).<br>Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote e-mail servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) POP3 or (2) IMAP response, as demonstrated by a certain +OK response on TCP port 110, aka "Outlook Express and Windows Mail Integer Overflow Vulnerability."  
References: [[CVE-2010-0816](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0816)] [[BID-40052](http://www.securityfocus.com/bid/40052)]<br>Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s" sequences to the pop3 port (110/tcp), which are expanded to "%%s" before being used in the memmove function, possibly due to an incomplete fix for [[CVE-2001-1078](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1078)].  
References: [[CVE-2007-5467](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5467)] [[BID-26074](http://www.securityfocus.com/bid/26074)] [SECUNIA-27220] | 0.6 |  |
| 111 | tcp,udp | SunRPC | Provides information between Unix based systems. Port is often probed, it can be used to fingerprint the Nix OS, and to obtain information about available services. Port used with NFS, NIS, or any rpc-based service.<br>Port 111 was designed by the Sun Microsystems as a component of their Network File System. It is also known as Open Network Computing Remote Procedure Call (ONC RPC). Port 111 is a port mapper with similar functions to Microsoft's port 135 or DCOM DCE.<br>Security Concerns: Provides rpc port map without auth, has no filtering or logging, rpcinfo probes can quickly find your Unix hosts. Shut down portmapper on any hosts not requiring rpcs, ensure it is blocked at net perimeters.<br>Trojans that use this port: ADM worm, MscanWorm, Sadmind/IIS Worm<br>NFS daemon (nfsd.exe) for Omni-NFS/X 6.1 allows remote attackers to cause a denial of service (resource exhaustion) via certain packets, possibly with the Urgent (URG) flag set, to port 111.  
References: [[CVE-1999-1349](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1349)]<br>PORTSERV.exe in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) TCP or (2) UDP packet to port 111.  
References: [[CVE-2012-1816](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1816)] [[BID-53591](http://www.securityfocus.com/bid/53591)] [SECUNIA-49210] [OSVDB-82012]<br>Vestel TV 42pf9322 is vulnerable to a denial of service. By sending a specially-crafted request containing an overlong string argument to port 111, a remote attacker could exploit this vulnerability to cause the device to malfunction.  
References: [[XFDB-87101](https://exchange.xforce.ibmcloud.com/vulnerabilities/87101)] [[BID-62394](http://www.securityfocus.com/bid/62394)] [[EDB-28271](https://www.exploit-db.com/exploits/28271/)]<br>MiCOM C264 could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow in the RPC service. By sending specially-crafted data to port 111, an attacker could overflow a buffer and execute arbitrary code on the system with elevated privileges.  
References: [[XFDB-111158](https://exchange.xforce.ibmcloud.com/vulnerabilities/111158)]<br>Vulnerability in BrightStor ARCserve Backup, can be exploited and cause a DoS (Denial of Service). The vulnerability is caused due to a NULL pointer dereference error when handling TADDR2UADDR (0x08) request types within the CA Remote Procedure Call Server service (CATIRPC.EXE). This can be exploited to crash the service by sending a specially crafted packet to port 111/UDP.  
References: [[CVE-2007-0816](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0816)] [SECUNIA-24009]<br>The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumption if an overcommit setting is not used) via a crafted UDP packet to port 111, a related issue to [CVE-2017-8779](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8779).  
References: [[CVE-2017-8804](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8804)], [[BID-98339](http://www.securityfocus.com/bid/98339)]<br>rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to port 111, aka rpcbomb.  
References: [[CVE-2017-8779](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8779)], [[BID-98325](http://www.securityfocus.com/bid/98325)]<br>On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). External packets destined to port 111 should be dropped. Due to an information leak vulnerability, responses were being generated from the source address of the management interface (e.g. fxp0) thus disclosing internal addressing and existence of the management interface itself. A high rate of crafted packets destined to port 111 may also lead to a partial Denial of Service (DoS). Note: Systems with fxp0 disabled or unconfigured are not vulnerable to this issue. This issue only affects Junos OS releases based on FreeBSD 10 or higher (typically Junos OS 15.1+). Administrators can confirm whether systems are running a version of Junos OS based on FreeBSD 10 or higher by typing: user@junos> show version | match kernel JUNOS OS Kernel 64-bit [20181214.223829_fbsd-builder_stable_10] Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F6-S12, 15.1R7-S4; 15.1X53 versions prior to 15.1X53-D236; 16.1 versions prior to 16.1R7-S1; 16.2 versions prior to 16.2R2-S9; 17.1 versions prior to 17.1R3; 17.2 versions prior to 17.2R1-S8; 17.3 versions prior to 17.3R2; 17.4 versions prior to 17.4R1-S1, 17.4R1-S7, 17.4R2. This issue does not affect Junos OS releases prior to 15.1.  
References: [[CVE-2019-0040](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0040)], [[BID-107902](http://www.securityfocus.com/bid/107902)], [[XFDB-159358](https://exchange.xforce.ibmcloud.com/vulnerabilities/159358)] | 0.6 |  |
| 113 | tcp,udp | IDENT | Port 113 used for Identification/Authorization service. When a client program on your end contacts a remote server for services such as POP, IMAP, SMTP, IRC, FTP, etc. that remote server sends back a query to the IDENT port 113 asking for identification from your system...<br>Port 113 can be probed by attackers and it poses some security concerns, but the problem with filtering/stealthing port 113 is that if legitimate requests get no response at all from port 113 queries, the connection to them (which initiated their query in the first place) will be delayed or perhaps even completely abandoned.<br>The simplest solution is to close, rather than filter port 113.<br>Some trojans also use this port: ADM worm, Alicia, Cyn, DataSpy Network X, Dosh, Gibbon, Invisible Identd Deamon, Kazimas, Taskman,W32.Korgo.F  
W32.Bofra.C@mm [[Symantec-2004-111113-3948-99](https://www.symantec.com/security-center/writeup/2004-111113-3948-99)] (2004.11.11) - It opens ports 1639/tcp and 1640/tcp for listening, opens an ident daemon on port 113/tcp, connects to IRC servers on port 6667/tcp.  
W32.Linkbot.A [[Symantec-2004-110516-3932-99](https://www.symantec.com/security-center/writeup/2004-110516-3932-99)] (2004.11.05) - worm that exploits the MS Windows LSASS Buffer Overrun Vulnerability. It also creates an IRC backdoor and attempts to install adware on the infected machine. It can affect all current Windows versions. Listens on port 113/tcp for remote commands.  
W32.Spybot.LZI [[Symantec-2005-040609-3623-99](https://www.symantec.com/security-center/writeup/2005-040609-3623-99)] (2005.04.06) - worm that attempts to exploit the MS DCOM RPC vulnerability on ports 135, 445 & 1025. Opens a backdoor on port 113.  
W32.Linkbot.M [[Symantec-2005-052109-2651-99](https://www.symantec.com/security-center/writeup/2005-052109-2651-99)] (2005.05.21) - opens a backdoor on port 6667/tcp. Also listens on port 113/tcp.<br>Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long string to TCP port 113.  
References: [[CVE-2007-2711](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2711)] [[BID-23981](http://www.securityfocus.com/bid/23981)] [SECUNIA-25248] [OSVDB-36053] | 0.9 |  |
| 135 | tcp,udp | LOC-SRV | Remote Procedure Call (RPC) port 135 is used in client/server applications (might be on a single machine) such as Exchange clients, the recently exploited messenger service, as well as other Windows NT/2K/XP software. If you have remote users who VPN into your network, you might need to open this port on the firewall to allow access to the Exchange server.<br>There is a RPC (a RPC's Endpoint Mapper component) vulnerability in Windows NT where a malformed request to port 135 could cause denial of service (DoS). RPC contains a flaw that causes it to fail upon receipt of a request that contains a particular type of malformed data. To restore normal functionality victim has to reboot the system. Alternatively, you can upgrade/patch your OS (there is patch downloadable from Microsoft), or you can close port 135.<br>Port 135 is used by Messenger Service (not MSN Messenger) and exploited in popup net send messenger spam [MSKB 330904]. To stop the popups you'd need to filter port 135 at the firewall level or stop the messenger service. The service uses all the following ports: 135/tcp, 135/udp, 137/udp 138/udp, 139/tcp, 445/tcp.<br>MS Security Bulletin [[MS03-026](http://technet.microsoft.com/en-us/security/bulletin/MS03-026)] outlines another critical Buffer Overrun RPC vulnerability that can be exploited via ports 135, 139, 445, 593 (or any other specifically configured RPC port). You should filter the above mentioned ports at the firewall level and not allow RPC over an unsecure network, such as the Internet.<br>W32.Blaster.Worm [[Symantec-2003-081113-0229-99](https://www.symantec.com/security-center/writeup/2003-081113-0229-99)] - a widely spread worm that exploits the DCOM RPC vulnerability described above (MS Security Bulletin [[MS03-026](http://technet.microsoft.com/en-us/security/bulletin/MS03-026)]). The worm allows remote access to an infected computer via ports 4444/tcp and 69/UDP, and spreads through port 135/tcp. To avoid being infected consider closing those ports.<br>Port is also used by Messenger Service (not MSN Messenger) and exploited in popup net send messenger spam [MSKB 330904]. To stop the popups you'd need to filter port 135 at the firewall level or stop the messenger service. The service uses all the following ports: 135/tcp, 135/udp, 137/udp 138/udp, 139/tcp, 445/tcp.<br>W32.Reatle.E@mm [[Symantec-2005-080215-5809-99](https://www.symantec.com/security-center/writeup/2005-080215-5809-99)] - a mass-mailing worm that opens a backdoor and also spreads by exploiting the MS DCOM RPC Vulnerability [[MS03-026](http://technet.microsoft.com/en-us/security/bulletin/MS03-026)] on port 135/tcp. It uses its own SMTP engine to email itself to gathered email addresses. Opens an FTP server on port 1155/tcp. Opens a proxy server on port 2005/tcp. It also attempts to perform denial of service (DDoS) attack agains known security websites on port 1052/tcp. *Note: port 1052 corresponds to the dynamic DNS service.*<br>A vulnerability has been identified in LOGO!8 BM (incl. SIPLUS variants) (All versions). The vulnerability could lead to an attacker reading and modifying the device configuration and obtain project files from affected devices. The security vulnerability could be exploited by an unauthenticated attacker with network access to port 135/tcp. No user interaction is required to exploit this security vulnerability. The vulnerability impacts confidentiality, integrity, and availability of the device. At the time of advisory publication no public exploitation of this security vulnerability was known.  
References: [[CVE-2020-7589](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7589)], [[XFDB-183129](https://exchange.xforce.ibmcloud.com/vulnerabilities/183129)] | 0.9 |  |
| 139 | tcp,udp | NetBIOS | NetBIOS is a protocol used for File and Print Sharing under all current versions of Windows. While this in itself is not a problem, the way that the protocol is implemented can be. There are a number of vulnerabilities associated with leaving this port open.<br>**NetBios services:**  
NETBIOS Name Service (TCP/UDP: 137)  
NETBIOS Datagram Service (TCP/UDP: 138)  
NETBIOS Session Service (TCP/UDP: 139)<br>By default, when File and Print Sharing is enabled it binds to everything, including TCP/IP (The Internet Protocol), rather than just the local network, meaning your shared resources are available over the entire Internet for reading and deletion, unless configured properly. Any machine with NetBIOS enabled and not configured properly should be considered at risk. The best protection is to turn off File and Print Sharing, or block ports 135-139 completely. If you must enable it, use the following guidelines:<br>1. Use strong passwords, containing non-alphanumeric characters.
2. Attach "$" at the end of your share names (the casual snooper using net view might not see them).
3. Unbind File and Print Sharing from TCP/IP and use NetBEUI instead (it's a non-routable protocol).
4. Block ports 135-139 in your router/firewall.<br>Keep in mind that you might still be leaking out information about your system that can be used against you (such as your computer and workgroup names) to the entire Internet, unless ports are filtered by a firewall.<br>There is also a Critical Windows RPC vulnerability affecting ports 135,139 and 445, as detailed here: MS Technet Security Bulletin [[MS03-026](http://technet.microsoft.com/en-us/security/bulletin/MS03-026)]<br>The following trojans/backdoors also use these ports:  
Chode, God Message worm, Msinit, Netlog, Network, Qaz<br>W32.HLLW.Moega [[Symantec-2003-080813-3234-99](https://www.symantec.com/security-center/writeup/2003-080813-3234-99)]<br>W32.Reidana.A [[Symantec-2005-032515-4042-99](https://www.symantec.com/security-center/writeup/2005-032515-4042-99)] (2005.03.27) - worm that spreads using the MS DCOM RPC vulnerability (MS Security Bulletin [[MS03-026](http://technet.microsoft.com/en-us/security/bulletin/MS03-026)]) on port 139. The worm attempts to download and execute a remote file via FTP. Opens TCP port 4444.<br>W32.Klez worm [[Symantec-2002-031910-1028-99](https://www.symantec.com/security-center/writeup/2002-031910-1028-99)] - a class of worms that collects email addresses from an infected computer's Windows address book and propagates using its own SMTP server. As of April 26, 2002, there are nine variants of the Klez worm that all exploit the "Microsoft Internet Explorer Incorrect MIME header" vulnerability, which causes an email attachment to be automatically executed when an HTML email is previewed by a Microsoft Outlook or Outlook Express user. The worm can arrive as an email attachment with one of the following file extensions: asp, bak, c, cpp, doc, htm, html, jpg, mp3, mpg, mpeg, pas, rtf, wab, or xls.<br>W32.Sircam.Worm [[Symantec-2001-071720-1640-99](https://www.symantec.com/security-center/writeup/2001-071720-1640-99)] - a computer worm that propagates by e-mail from Microsoft Windows systems. It also spreads via open shares on a network. Sircam scans the network for computers with shared drives and copy itself to a machine with an open (non-password protected) drive or directory.<br>Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0.225, 5.1 before 5.1.0.106, and 5.2 before 5.2.0.238 on Windows allows remote attackers to execute arbitrary code via a crafted SMB packet in a TCP session on port (1) 139 or (2) 445.  
References: [[CVE-2007-5580](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5580)] [[BID-26723](http://www.securityfocus.com/bid/26723)] [SECUNIA-27947] [OSVDB-39521]<br>Server Message Block (SMB) also uses this port. It is used by Microsoft Windows file and print services, such as Windows Sharing in Mac OS X. | 0.9 |  |
| 143 | tcp,udp | IMAP | IMAP (Internet Mail Access Protocol) mail server uses this port. See also port 993/tcp.<br>Numerous IMAP servers have buffer overflows that allow compromise during the login. Note that for awhile, there was a Linux worm (admw0rm) that would spread by compromising port 143, so a lot of scans on this port are actually from innocent people who have already been compromised. IMAP exploits became popular when Red Hat enabled the service by default on its distributions. This port is also used for IMAP2, but that version wasn't very popular. Several people have noted attacks from port 0 to port 143, which appears to be from some attack script.<br>MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application crash) via a long string to IMAP port (143/tcp).  
References: [[CVE-2008-1713](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1713)] [[BID-28559](http://www.securityfocus.com/bid/28559)] [SECUNIA-29629]<br>Format string vulnerability in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit imap-2007d and other applications, allows remote attackers to execute arbitrary code via format string specifiers in the initial request to the IMAP port (143/tcp). NOTE: Red Hat has disputed the vulnerability, stating "The Red Hat Security Response Team have been unable to confirm the existence of this format string vulnerability in the toolkit, and the sample published exploit is not complete or functional." CVE agrees that the exploit contains syntax errors and uses Unix-only include files while invoking Windows functions.  
References: [[CVE-2009-0671](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0671)] [[BID-33795](http://www.securityfocus.com/bid/33795)]<br>ADM trojan also uses this port (TCP). | 0.9 |  |
| 179 | tcp,udp,sctp | BGP | Border Gateway Protocol (IANA official)  
See also [[RFC 4960](http://tools.ietf.org/html/rfc4960)]<br>Brocade BigIron RX switches allow remote attackers to bypass ACL rules by using 179 as the source port of a packet.  
References: [[CVE-2011-2760](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2760)] [[BID-48663](http://www.securityfocus.com/bid/48663)] [SECUNIA-45217] [OSVDB-73869] | 0.9 |  |
| 199 | tcp,udp | SMUX | IANA registered for: SMUX | 1 |  |
| 443<br>- clickable [https://website](http://website) | tcp | HTTPS | HTTPS / SSL - encrypted web traffic, also used for VPN tunnels over HTTPS.<br>Apple applications that use this port: Secured websites, iTunes Store, FaceTime, MobileMe (authentication) and MobileMe Sync.<br>ASUS AiCloud routers file sharing service uses ports 443 and 8082. There is a vulnerability in AiCloud with firmwares prior to 3.0.4.372 , see [[CVE-2013-4937](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4937)]<br>Ubiquiti UniFi Cloud Access uses ports 443 TCP/UDP, 3478 UDP, 8883 TCP.<br>SoftEther VPN (Ethernet over HTTPS) uses TCP Ports 443, 992 and 5555<br>Ooma VoIP - uses UDP port 1194 (VPN tunnel to the Ooma servers for call/setup control), ports 49000-50000 for actual VoIP data, and ports TCP 443, UDP 514, UDP 3480<br>Open Mobile Alliance (OMA) Device Management uses port 443/TCP.<br>Cisco Webex Teams services uses these ports:  
443,444,5004 TCP  
53, 123, 5004, 33434-33598 UDP (SIP calls)<br>Syncthing listens on TCP ports 443, 22067, 22070<br>AnyDesk remote desktop software uses TCP ports 80, 443, 6568, 7070 (direct line connection)<br>Call of Duty World at War uses this port.<br>Trojans that use this port:  
W32.Kelvir.M [[Symantec-2005-040417-3944-99](https://www.symantec.com/security-center/writeup/2005-040417-3944-99)] (2005.04.04) - worm that spreads through MSN Messanger and drops a variant of the W32.Spybot.Worm [[Symantec-2003-053013-5943-99](https://www.symantec.com/security-center/writeup/2003-053013-5943-99)]. Connects to IRC servers on the [s.defonic2.net](http://s.defonic2.net) and [s.majesticwin.com](http://s.majesticwin.com) domains, and listens for commands on port 443/tcp.<br>Directory traversal vulnerability in Cisco Network Admission Control (NAC) Manager 4.8.x allows remote attackers to read arbitrary files via crafted traffic to TCP port 443, aka Bug ID CSCtq10755.  
References: [[CVE-2011-3305](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3305)] [[BID-49954](http://www.securityfocus.com/bid/49954)]<br>Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.  
References: [[CVE-2010-3036](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3036)] [[BID-44468](http://www.securityfocus.com/bid/44468)] [SECUNIA-42011] [OSVDB-68927]<br>Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port 443/tcp.  
References: [[CVE-2008-0401](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0401)] [[BID-27387](http://www.securityfocus.com/bid/27387)] [SECUNIA-28604]<br>The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn99724.  
References: [[CVE-2012-3075](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3075)]<br>Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 443, aka Bug ID CSCty20405.  
References: [[CVE-2013-5531](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5531)]<br>The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.3 before 1.1.3.124-7, 1.1.4 before 1.1.4.218-7, and 1.2 before 1.2.0.899-2 allows remote authenticated users to execute arbitrary commands via a crafted session on TCP port 443, aka Bug ID CSCuh81511.  
References: [[CVE-2013-5530](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5530)]<br>Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 443.  
References: [[CVE-2016-3963](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3963)]<br>Siemens SIMATIC S7-1200 is vulnerable to a denial of service, caused by an error when handling specially-crafted HTTPS traffic passed to TCP port 443. By sending specially-crafted packets to TCP port 443, a remote attacker could exploit this vulnerability to cause the device to go into defect mode.  
References: [[CVE-2014-2258](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2258)] [[XFDB-92059](https://exchange.xforce.ibmcloud.com/vulnerabilities/92059)]<br>A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack on the integrated web server on port 443/tcp.  
References: [[CVE-2017-6873](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6873)], [[BID-99473](http://www.securityfocus.com/bid/99473)]<br>A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the web server by sending specially crafted network packets to port 443/TCP or port 80/TCP.  
References: [[CVE-2017-6869](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6869)], [[BID-99343](http://www.securityfocus.com/bid/99343)]<br>A vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCALANCE X414 (All versions). The web interface on port 443/tcp could allow an attacker to cause a Denial-of-Service condition by sending specially crafted packets to the web server. The device will automatically reboot, impacting network availability for other devices. An attacker must have network access to port 443/tcp to exploit the vulnerability. Neither valid credentials nor interaction by a legitimate user is required to exploit the vulnerability. There is no confidentiality or integrity impact, only availability is temporarily impacted. This vulnerability could be triggered by publicly available tools.  
References: [[CVE-2018-13807](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13807)], [[BID-105331](http://www.securityfocus.com/bid/105331)] | 1 |  |
| 445 | tcp | Microsoft-DS | TCP port 445 is used for direct TCP/IP MS Networking access without the need for a NetBIOS layer. This service is only implemented in the more recent verions of Windows (e.g. Windows 2K / XP). The SMB (Server Message Block) protocol is used among other things for file sharing in Windows NT/2K/XP. In Windows NT it ran on top of NetBT (NetBIOS over TCP/IP, ports 137, 139 and 138/udp). In Windows 2K/XP, Microsoft added the possibility to run SMB directly over TCP/IP, without the extra layer of NetBT. For this they use TCP port 445.<br>Microsoft Lync server uses these ports:  
444, 445, 448, 881, 5041, 5060 - 5087, 8404 TCP  
80, 135, 443, 4443, 8060, 8061, 8080 TCP - standard ports and HTTP(s) traffic  
1434 UDP - SQL  
49152-57500 TCP/UDP - media ports<br>Port 445 should be blocked at the firewall level. It can also be disabled by deleting the HKLM\System\CurrentControlSet\Services \NetBT\Parameters\TransportBindName (value only) in the Windows Registry.<br>Leaving port 445 open leaves Windows machines vulnerable to a number of trojans and worms:  
W32.HLLW.Deloder [[Symantec-2003-030812-5056-99](https://www.symantec.com/security-center/writeup/2003-030812-5056-99)]  
IraqiWorm (aka Iraq_oil.exe )  
W32.HLLW.Moega [[Symantec-2003-080813-3234-99](https://www.symantec.com/security-center/writeup/2003-080813-3234-99)]  
W32.Korgo.AB [[Symantec-2004-092415-4853-99](https://www.symantec.com/security-center/writeup/2004-092415-4853-99)] (2004.09.24)  
Backdoor.Rtkit.B [[Symantec-2004-100115-0426-99](https://www.symantec.com/security-center/writeup/2004-100115-0426-99)] (2004.10.01)  
W32.Sasser.Worm [[Symantec-2004-050116-1831-99](https://www.symantec.com/security-center/writeup/2004-050116-1831-99)] - exploits port 445 vulnerabilities, opens TCP ports 5554,9996.  
Trojan.Netdepix.B [[Symantec-2005-011715-5404-99](https://www.symantec.com/security-center/writeup/2005-011715-5404-99)] (2005.01.16.) - trojan uses port 445, opens port 15118/tcp.  
Backdoor.IRC.Cirebot [[Symantec-2003-080214-3019-99](https://www.symantec.com/security-center/writeup/2003-080214-3019-99)] (2003.08.02) - trojan that exploits the MS DCOM vulnerability, uses ports 445 & 69, opens backdoor on port 57005.  
[Windows Null Session Exploit](http://www.brown.edu/Facilities/CIS/CIRT/help/netbiosnull.html).<br>MS Security Bulletin [[MS03-026](http://technet.microsoft.com/en-us/security/bulletin/MS03-026)] outlines a critical RPC vulnerability that can be exploited via ports 135, 139, 445, 593 (or any other specifically configured RPC port). You should filter the above mentioned ports at the firewall level and not allow RPC over an unsecure network, such as the Internet.<br>See also: Microsoft Security Bulletin [[MS03-049](http://technet.microsoft.com/en-us/security/bulletin/MS03-049)] and Microsoft Security Bulletin [[MS03-043](http://technet.microsoft.com/en-us/security/bulletin/MS03-043)]<br>W32.Zotob.C@mm [[Symantec-2005-081516-4417-99](https://www.symantec.com/security-center/writeup/2005-081516-4417-99)] (2005.08.16) - mass-mailing worm that opens a backdoor and exploits the MS Plug and Play Buffer Overflow vulnerability (MS Security Bulletin [[MS05-039](http://technet.microsoft.com/en-us/security/bulletin/MS05-039)]) on port 445/tcp. It connects to IRC servers and listens for remote commands on port 8080/tcp. It also opens an FTP server on port 33333/tcp. Same ports are used by the W32.Zotob.A [[Symantec-2005-081415-0646-99](https://www.symantec.com/security-center/writeup/2005-081415-0646-99)] and W32.Zotob.B [[Symantec-2005-081415-0741-99](https://www.symantec.com/security-center/writeup/2005-081415-0741-99)] variants of the worm as well.<br>W32.Zotob.D [[Symantec-2005-081609-4733-99](https://www.symantec.com/security-center/writeup/2005-081609-4733-99)] (2005.08.16) - a worm that opens a backdoor and exploits the MS Plug and Play Buffer Overflow vulnerability (MS Security Bulletin [[MS05-039](http://technet.microsoft.com/en-us/security/bulletin/MS05-039)]) on port 445/tcp. Conects to IRC servers to listen for remote commands on port 6667/tcp. Also opens an FTP server on port 1117/tcp.<br>W32.Zotob.E [[Symantec-2005-081615-4443-99](https://www.symantec.com/security-center/writeup/2005-081615-4443-99)] (2005.08.16) - a worm that opens a backdoor and exploits the MS Plug and Play Buffer Overflow vulnerability (MS Security Bulletin [[MS05-039](http://technet.microsoft.com/en-us/security/bulletin/MS05-039)]) on port 445/tcp. It runs and spreads using all current Windows versions, but only infects Windows 2000.  
The worm connects to IRC servers and listens for remote commands on port 8080/tcp. It opens port 69/udp to initiate TFTP transfers. It also opens a backdoor on remote compromised computers on port 8594/tcp.<br>W32.Zotob.H [[Symantec-2005-081717-2017-99](https://www.symantec.com/security-center/writeup/2005-081717-2017-99)]<br>[W32.Conficker.worm](https://kc.mcafee.com/corporate/index?page=content&id=KB60909) - a worm with multiple variants. It exploits a buffer overflow vulnerability in the Server Service on Windows computers. McAfee has named the most recently discovered variant of this worm as W32/Conficker.worm.gen.d. The original W32.Conficker.worm attacks port 445, the port that Microsoft Directory Service uses, and exploits Microsoft Windows vulnerability [[MS08-067](http://technet.microsoft.com/en-us/security/bulletin/MS08-067)].<br>Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0.225, 5.1 before 5.1.0.106, and 5.2 before 5.2.0.238 on Windows allows remote attackers to execute arbitrary code via a crafted SMB packet in a TCP session on port (1) 139 or (2) 445.  
References: [[CVE-2007-5580](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5580)] [[BID-26723](http://www.securityfocus.com/bid/26723)] [SECUNIA-27947] [OSVDB-39521]<br>LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.  
References: [[CVE-2002-0597](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0597)] [[BID-4532](http://www.securityfocus.com/bid/4532)] [OSVDB-5179] | 0.3 |  |
| 465 | tcp | SMTP-SSL | Outgoing SMTP Mail over SSL (SMTPS) [[RFC 2487](http://tools.ietf.org/html/rfc2487)] - older IANA registered port, largely replaced by port 587 and SMTP over TLS.<br>PlayStation Network and SCEA Game Servers use this port<br>Datalust Seq.App.EmailPlus (aka seq-app-htmlemail) 3.1.0-dev-00148, 3.1.0-dev-00170, and 3.1.0-dev-00176 can use cleartext SMTP on port 25 in some cases where encryption on port 465 was intended.  
References: [[CVE-2021-43270](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43270)]<br>Message Submission over TLS protocol [[RFC8314](http://tools.ietf.org/html/rfc8314)] (IANA official) | 0.8 |  |
| 514 | tcp | shell | Used by rsh and (also rcp), interactive shell without any logging.<br>Citrix NetScaler appliance MAS syslog port.<br>Splunk (big data analysis software) uses the following ports by default:  
514 - network input port  
8000 - web port (clients accessing the Splunk search page)  
8080 - index replication port  
8089 - management port (splunkd, aslo used by deployment server)  
9997 - indexing port (web interface)  
9998 - SSL port<br>Fortinet FortiGate uses the following ports (in addition to standard ports 53, 80, 443):  
514 tcp - FortiAP logging and reporting  
541 tcp, 542 tcp - FortiGuard management  
703 tcp/udp. 730 udp - FortiGate heartbeat  
1000 tcp, 1003 tcp - policy override keepalive  
1700 tcp - FortiAuthenticator RADIUS disconnect  
5246 udp - FortiAP-S event logs  
8000, 8001 tcp - FortiClient SSO mobility agent  
8008, 8010 tcp - policy override authentication  
8013 tcp - FortiClient v.5.4  
8014 tcp - Forticlient v.6  
8890 tcp - AV/IPS updates, management, firmware  
9443 udp - AV/IPS  
9582 tcp - FortiGuard Cloud App DB ([flow.fortinet.net](http://flow.fortinet.net))<br>Games that use this port: America's Army<br>Malware using this port: RPC Backdoor, Whacky, ADM worm<br>Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary code via a long string to the shell port (514/tcp). NOTE: this might overlap [[CVE-2007-4006](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4006)].  
References: [[CVE-2007-4005](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4005)] [[BID-25044](http://www.securityfocus.com/bid/25044)] [SECUNIA-26197]<br>Denicomp RSHD 2.18 and earlier allows a remote attacker to cause a denial of service (crash) via a long string to port 514.  
References: [[CVE-2001-0707](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0707)]<br>A vulnerability has been reported in Cisco IOS, which can be exploited to cause a DoS (Denial of Service). The vulnerability is caused due to TCP connection information not being properly validated when connecting to a protocol translation resource and can be exploited to cause a reload via specially crafted packets sent to TCP ports 514 or 544. Successful exploitation requires a vulnerable protocol translation configuration or a Telnet-to-PAD protocol translation ruleset to be configured.  
References: [[CVE-2013-1147](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1147)] [SECUNIA-52785] | 0.8 |  |
| 515 | tcp | Printing Server | Printing services, listening for incoming connections<br>Trojans using this port: MscanWorm, lpdw0rm, Ramen.<br>Multiple buffer overflows in Client Software WinCom LPD Total 3.0.2.623 and earlier allow remote attackers to execute arbitrary code via a long 0x02 command to the remote administration service on TCP port 13500 or a long invalid control filename to LPDService.exe on TCP port 515.  
References: [[CVE-2008-5176](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5176)], [[BID-27614](http://www.securityfocus.com/bid/27614)]<br>Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to execute arbitrary code via a long string in a request to TCP port 515.  
References: [[CVE-2006-3670](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3670)] [SECUNIA-21058] [[BID-19011](http://www.securityfocus.com/bid/19011)] [OSVDB-27332]<br>Buffer overflow in NIPrint 4.10 allows remote attackers to execute arbitrary code via a long string to TCP port 515.  
References: [[CVE-2003-1141](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1141)] [[BID-8968](http://www.securityfocus.com/bid/8968)] [OSVDB-2774] [SECUNIA-10143]<br>SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515.  
References: [[CVE-2016-10079](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10079)], [[EDB-41030](https://www.exploit-db.com/exploits/41030/)]<br>spooler (IANA official) | 0.9 |  |
| 548 | tcp | afpovertcp | AppleShare, Personal File Sharing, Apple File Service<br>ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allows remote attackers to cause a denial of service (daemon crash) via an invalid UAM field in a request to the Apple Filing Protocol (AFP) service on TCP port 548.  
References: [[CVE-2008-0759](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0759)], [[BID-27718](http://www.securityfocus.com/bid/27718)]<br>Novell Netware is vulnerable to a denial of service, caused by a NULL pointer dereference in the AFPTCP.nlm module. By sending a specially-crafted AFP request to TCP port 548, a remote attacker could exploit this vulnerability to cause the application to crash.  
References: [[CVE-2010-0317](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0317)], [[XFDB-55389](https://exchange.xforce.ibmcloud.com/vulnerabilities/55389)], [[BID-37616](http://www.securityfocus.com/bid/37616)], [OSVDB-61604] | 0.9 |  |
| 554 | tcp | MS-RTSP | Port used by Real Time Streaming Protocol (RTSP) for Microsoft Windows Media streaming services and QuickTime Streaming Server (QTSS).<br>RTSP uses the following ports:  
554 TCP - used for accepting incoming RTSP client connections and for delivering data packets to clients that are streaming by using RTSPT.  
5004 UDP - used for delivering data packets to clients that are streaming by using RTSPU.  
5005 UDP - used for receiving packet loss information from clients and providing synchronization information to clients that are streaming by using RTSPU.<br>Multiple Vivotek IP Camera products could allow a remote attacker to bypass security restrictions, caused by the improper validation of input. If RTSP authentication is set to basic, an attacker could send a specially-crafted request to TCP port 554 in order to bypass authentication and gain access to the RTSP live video stream.  
References: [[CVE-2013-4985](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4985)] [[XFDB-88567](https://exchange.xforce.ibmcloud.com/vulnerabilities/88567)] [[EDB-29516](https://www.exploit-db.com/exploits/29516/)]<br>Multiple Vivotek IP Cameras products could allow a remote attacker to bypass security restrictions, caused by the failure to restrict access to the video stream. By sending specially-crafted RTSP packets to TCP port 554, an attacker could exploit this vulnerability to access the video stream without authentication.  
References: [[CVE-2013-1596](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1596)] [[XFDB-83945](https://exchange.xforce.ibmcloud.com/vulnerabilities/83945)] [[BID-59574](http://www.securityfocus.com/bid/59574)]<br>See also: port 1755 - Microsoft Media Server (MMS) protocol | 0.9 |  |
| 587 | tcp | SMTP | Outgoing SMTP Mail port (TLS/Start TLS Port) - used by various mail servers for relaying outgoing mail as a modern alternative to port 25. Gmail, Apple MobileMe Mail, Yahoo SMTP server, etc. all use this port. See [[RFC2476](http://tools.ietf.org/html/rfc2476)]<br>IANA registered for: Message Submission (TCP/UDP) | 1 |  |
| 646 | tcp,udp |  | LDP, Label Distribution Protocol, a routing protocol used in MPLS networks (official) | 1 |  |
| 993 | tcp | IMAP-SSL | IMAP over SSL | 1 |  |
| 995 | tcp | POP3-SSL | Incoming POP3 mail over SSL  
used by Gmail | 1 |  |
| 1025-1029 | tcp,udp | NFC-IIS | Ports > 1024 are designated for dynamic allocation by Windows. When programs ask for the "next available" socket, they usually get sequential ports starting at 1025.<br>Ports 1026-1027/udp were historically used for Windows Messenger popup spam<br>NFS  
IIS  
Teradata  
ShopPro accounting software<br>Trojans that use this port: NetSpy, Maverick's Matrix, RemoteStorm (TCP/UDP)<br>network blackjack (TCP/UDP) (IANA official) | 1 |  |
| 1433 | tcp | Microsoft SQL | Microsoft SQL Server.<br>Vulnerabilities: Check CERT advisories CA-2002-22 - multiple vulnerabilities, CA-2003-04 MS SQL Server Worm. See also Microsoft Security Bulletin [[MS02-061](http://technet.microsoft.com/en-us/security/bulletin/MS02-061)].<br>The [Gaobot](http://www.sarc.com/avcenter/venc/data/w32.gaobot.aay.html) family of worms also exploit this port.<br>IBM License Metric Tool ports  
1433 TCP - SQL server connection  
9081 TCP - HTTPS web browser connections to server  
50000 TCP - DB2 server connection  
52311 TCP - BigFix clients and console connect to the server<br>Digispid.B.Worm [[Symantec-2002-052108-5430-99](https://www.symantec.com/security-center/writeup/2002-052108-5430-99)] (2002.05.21) - worm that spreads to computers running MS SQL server and have blank SQL admin password. Uses port 1433/tcp.  
W32.Kelvir.R [[Symantec-2005-041214-1218-99](https://www.symantec.com/security-center/writeup/2005-041214-1218-99)] (2005.04.12) - worm that spreads through MSN messenger and drops a variant of W32.Spybot.Worm. It spreads using several known MS vulnerabilities, including MS security Bulletin [[MS02-061](http://technet.microsoft.com/en-us/security/bulletin/MS02-061)] Microsoft SQL Server 2000 or MSDE 2000 audit using port 1434/udp.<br>Buffer overflow in the authentication function for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows remote attackers to execute arbitrary code via a long request to TCP port 1433, a.k.a. the "Hello" overflow.  
References: [[CVE-2002-1123](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1123)], [[BID-5411](http://www.securityfocus.com/bid/5411)]<br>The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request to TCP port 1433.  
References: [[CVE-2014-4684](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4684)] | Fail |  |
| 1720 | tcp | h323 | Port most commonly used by Microsoft NetMeeting.  
H.323 used for voice-over IP call set-up (H.323 Call Control Signalling, IANA official).  
IPContact also uses port 1720 (TCP/UDP)<br>Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) by sending crafted H.323 packets to TCP port 1720, aka Bug ID CSCth11006.  
References: [[CVE-2011-3277](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3277)], [[BID-49822](http://www.securityfocus.com/bid/49822)]<br>innovaphone is vulnerable to a denial of service. By sending random data to its H.323 network service on the TCP port 1720, a remote attacker could exploit this vulnerability to cause the system to reboot.  
References: [[XFDB-111292](https://exchange.xforce.ibmcloud.com/vulnerabilities/111292)]<br>An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.  
References: [[CVE-2020-14305](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14305)] | 0.8 |  |
| 1723 | tcp,udp | PPTP | PPTP VPN (Point-to-Point Tunneling Protocol Virtual Private Networking).<br>PPTP has a number of known vulnerabilities. It is no longer considered secure, as cracking the initial MS-CHAPv2 authentication can be reduced to the difficulty of cracking a single DES 56-bit key, which can be brute-forced in a short period of time. It is prone to MITM (man in the middle) attacks, where an attacker can capture the handshake and do an offline attack to derive the RC4 key and decrypt the traffic. PPTP is also vulnerable to bit-flipping attacks, i.e. an attacker can modify PPTP packets without possibility of detection. OpenVPN with AES encryption is a much more secure choice.<br>See also:  
port 500/udp (IPSec IKE)  
port 1701/tcp (L2TP)  
port 1194/udp (OpenVPN)<br>QNAP NAS uses port 1723/TCP for PPTP VPN. It can also use 1194/UDP (OpenVPN), and a number of other ports, as follows: 80,8081/TCP (web server), 443,8080/TCP (web admin), 20,21,22/TCP (FTP/SSH), 13131/TCP (telnet), 873,8899/TCP (remote replication), 20001/UDP (CloudLink - optional, only required for access without manual port forwarding)<br>Mac OS X Server VPN service also uses port 1723 (TCP).<br>The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood of crafted TCP packets to port 1723.  
References: [[CVE-2009-3322](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3322)] [[BID-36366](http://www.securityfocus.com/bid/36366)]<br>SMC Networks Barricade Wireless Cable/DSL Broadband Router SMC7004VWBR allows remote attackers to cause a denial of service via certain packets to PPTP port 1723 on the internal interface.  
References: [[CVE-2003-0419](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0419)]<br>The PPTP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via crafted TCP port-1723 packets, aka Bug ID CSCtq14817.  
References: [[CVE-2013-5481](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5481)] | 0.8 |  |
| 2000<br>- clickable [http://website](http://website):2000 | tcp | callbook | "RemoteAnywhere" installs a webserver on this port. NeWS/OpenWin (Sun's older variation of X-Windows) uses this port.<br>Lineage also uses this port.<br>A number of trojan horses/backdoors use this port: TransScout, Der Spaeher, Fear, Force, GOTHIC Intruder, Insane Network, Last 2000, Real 2000, Remote Explorer 2000, Senna Spy Trojan Generator, Singularity  
Backdoor.Fearic [[Symantec-2002-080710-2744-99](https://www.symantec.com/security-center/writeup/2002-080710-2744-99)] (2002.08.07) - remote access trojan, affects all current Windows versions, opens ports 2000, 3456, 8811.  
Trojan.Esteems.D [[Symantec-2005-051615-2304-99](https://www.symantec.com/security-center/writeup/2005-051615-2304-99)] (2005.05.16) - trojan with keylogger capabilities. Uses port 2000/tcp to communicate with a remote host and send logged information.<br>Dark Colony game also uses port 2000 (TCP/UDP).<br>Unspecified vulnerability in the Session Border Controller (SBC) before 3.0(2) for Cisco 7600 series routers allows remote attackers to cause a denial of service (SBC card reload) via crafted packets to TCP port 2000.  
References: [[CVE-2009-0619](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0619)], [[BID-33975](http://www.securityfocus.com/bid/33975)]<br>Port is also IANA registered for Cisco SCCP | 0.9 |  |
| 2001 | tcp | Trojans | Some trojans/backdoors use this port: Der Spaeher, Duddie, Glacier, Protoss, Senna Spy Trojan Generator, Singularity, Trojan Cow. Port also used by FreeBSD.Scalper.Worm [[Symantec-2002-062814-5031-99](https://www.symantec.com/security-center/writeup/2002-062814-5031-99)] (2002.06.28) - FreeBSD Apache worm.<br>WellinTech KingView 6.53 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted packet to (1) TCP or (2) UDP port 2001.  
References: [[CVE-2012-1832](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1832)]<br>The Panda Antivirus console on port 2001 allows local users to execute arbitrary commands without authentication via the CMD command.  
References: [[CVE-2000-0541](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0541)] [[BID-1359](http://www.securityfocus.com/bid/1359)]<br>curry (IANA official) | 1 |  |
| 3306 | tcp,udp | MySQL | MySQL database server connections - [http://www.mysql.com](http://www.mysql.com)<br>MySQL 5.5.8, when running on Windows, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted packet to TCP port 3306.  
References: [[CVE-2011-5049](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5049)]<br>Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306 (note: the vendor disputes this issue).  
See: [[CVE-2016-6531](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6531)]<br>Caesar IV game uses this port.<br>Port also used by Nemog backdoor (discovered 2004.08.16) - a backdoor trojan horse that allows an infected computer to be used as an email relay and HTTP proxy, dropped by W32.Mydoom.Q@mm.  
It can use one of the following ports: 3306,4242,4646,4661,6565,8080<br>Worms using this port: W32.Spybot.IVQ [[Symantec-2005-012715-3315-99](https://www.symantec.com/security-center/writeup/2005-012715-3315-99)] | Fail |  |
| 3389 | tcp | RDP | Port is IANA registered for Microsoft WBT Server, used for Windows Remote Desktop and Remote Assistance connections ([RDP - Remote Desktop Protocol](https://docs.microsoft.com/en-us/windows/desktop/TermServ/remote-desktop-protocol)). Also used by Windows Terminal Server.<br>See also: MS Security Bulletin [[MS02-051](http://technet.microsoft.com/en-us/security/bulletin/MS02-051)] and [[MS01-040](http://technet.microsoft.com/en-us/security/bulletin/MS01-040)].<br>Trojans using this port: Backdoor.Win32.Agent.cdm [[Symantec-2005-050114-4234-99](https://www.symantec.com/security-center/writeup/2005-050114-4234-99)], TSPY_AGENT.ADDQ<br>This port is vulnerable to Denial of Service Attack Against Windows NT Terminal Server. A remote attacker can quickly cause a server to reach full memory utilization by creating a large number of normal TCP connections to port 3389. Individual connections will timeout, but a low bandwidth  
continuous attack will maintain a terminal server at maximum memory utilization and prevent new connections from a legitimate source from taking place. Legitimate new connections will fail at this point with an error of either a connection timeout, or the terminal server has ended the connection.  
References: [[CVE-1999-0680](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0680)]<br>A vulnerability exists in the Remote Desktop Protocol (RDP), where an attacker could send a specially crafted sequence of packets to TCP port 3389 which can result in RDP to accessing an object in memory after it has been deleted.  
References: [[CVE-2012-2526](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2526)]<br>Zmodo Geovision also uses port 3389 (TCP/UDP) | 0.01 |  |
| 5060 | tcp,udp | SIP | Session Initiation Protocol (SIP) (official) - SIP VoIP phones and providers use this port. Asterisk server, X-ten Lite/Pro, Ooma, Vonage (ports 5060,5061,10000-20000), Apple iChat, iTalkBB, Motorola Ojo, OpenWengo, TalkSwitch, IConnectHere, Lingo VoIP (ports 5060-5065)<br>Microsoft Lync server uses these ports:  
444, 445, 448, 881, 5041, 5060 - 5087, 8404 TCP  
80, 135, 443, 4443, 8060, 8061, 8080 TCP - standard ports and HTTP(s) traffic  
1434 UDP - SQL  
49152-57500 TCP/UDP - media ports<br>Siemens Openstage and Gigaset phones use the following ports:  
389/tcp LDAP  
636/tcp LDAPS  
5010/tcp - RTP  
5060/tcp - SIP gateway, backup proxy  
8085/tcp - DLS  
18443/TCP and 18444/TCP - provisioning over TLS (HTTPS)<br>Memory leak in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (memory consumption or device reload) by sending crafted SIP packets to UDP port 5060, aka Bug ID CSCtj04672.  
References: [[CVE-2011-3280](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3280)]<br>The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) via a malformed SIP packet to UDP port 5060, aka Bug ID CSCti98219.  
References: [[CVE-2011-3279](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3279)]<br>Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) by sending crafted SIP packets to UDP port 5060, aka Bug ID CSCti48483.  
References: [[CVE-2011-3278](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3278)]<br>Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) by sending crafted SIP packets to TCP port 5060, aka Bug ID CSCso02147.  
References: [[CVE-2011-3276](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3276)], [[BID-49822](http://www.securityfocus.com/bid/49822)]<br>Unspecified vulnerability in Cisco TelePresence C Series Endpoints, E/EX Personal Video units, and MXP Series Codecs, when using software versions before TC 4.0.0 or F9.1, allows remote attackers to cause a denial of service (crash) via a crafted SIP packet to port 5060 or 5061, aka Bug ID CSCtq46500.  
References: [[CVE-2011-2577](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2577)] [[BID-49392](http://www.securityfocus.com/bid/49392)]<br>Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and device reboot) via a crafted SIP packet to UDP port 5060.  
References: [[CVE-2008-7065](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7065)] [[BID-32451](http://www.securityfocus.com/bid/32451)] [SECUNIA-32827] [OSVDB-50274]<br>The Grandstream HT-488 0.1 allows remote attackers to cause a denial of service (device crash) via a flood of fragmented packets to port 5060.  
References: [[CVE-2007-5789](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5789)], [[BID-26349](http://www.securityfocus.com/bid/26349)]<br>Memory leak in Cisco Unified Communications Manager IM and Presence Service before 8.6(5)SU1 and 9.x before 9.1(2), and Cisco Unified Presence, allows remote attackers to cause a denial of service (memory and CPU consumption) by making many TCP connections to port (1) 5060 or (2) 5061, aka Bug ID CSCud84959.  
References: [[CVE-2013-3453](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3453)]<br>Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly restrict the rate of SIP packets, which allows remote attackers to cause a denial of service (memory and CPU consumption, and service disruption) via a flood of UDP packets to port 5060, aka Bug ID CSCub35869.  
References: [[CVE-2013-3461](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3461)]<br>Cisco TelePresence Video Communication Server is vulnerable to a denial of service, caused by the improper handling of messages by the Session Initiation Protocol (SIP) module. By sending a specially-crafted Session Description Protocol (SDP) message to UDP and TCP port 5060, a remote attacker could exploit this vulnerability to cause the device to reload.  
References: [[CVE-2014-0662](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0662)], [[BID-65076](http://www.securityfocus.com/bid/65076)], [[XFDB-90621](https://exchange.xforce.ibmcloud.com/vulnerabilities/90621)]<br>innovaphone is vulnerable to a denial of service, caused by improper bounds checking by protocol SIP/UDP. By sending a specially-crafted SIP request to the open 5060/UDP port, an remote attacker could exploit this vulnerability to cause the VoIP phone to crash and restart.  
References: [[XFDB-111764](https://exchange.xforce.ibmcloud.com/vulnerabilities/111764)]<br>A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper processing of SIP packets in transit while NAT is performed on an affected device. An unauthenticated, remote attacker could exploit this vulnerability by sending crafted SIP packets via UDP port 5060 through an affected device that is performing NAT for SIP packets. A successful exploit could allow an attacker to cause the device to reload, resulting in a denial of service (DoS) condition.  
References: [[CVE-2018-0476](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0476)], [[BID-105419](http://www.securityfocus.com/bid/105419)]<br>Polycom VVX 500/601 devices could allow a remote attacker to obtain sensitive information, caused by a flaw in the SIP service. By sending a specially-crafted request to TCP port 5060, a remote attacker could exploit this vulnerability to obtain phone configuration information.  
References: [[CVE-2018-18566](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18566)], [[XFDB-151919](https://exchange.xforce.ibmcloud.com/vulnerabilities/151919)], [[BID-105746](http://www.securityfocus.com/bid/105746)] | 0.9 |  |
| 5666 | tcp | applications | MOHAA Reverend, Nagios NRPE<br>PC Crasher trojan also uses this port.<br>IANA registered for: Nagios Remote Plugin Executor | 1 |  |
| 5900 | tcp | VNC | VNC (Virtual Network Computing) - remote control programs. VNC typically also uses ports 5800+ and 5900+ for additional machines.<br>Citrix NetScaler appliance Lights out Management uses ports 4001, 5900, 623 TCP to run a daemon that offers unified configuration management of routing protocols.<br>Backdoor.Evivinc [[Symantec-2004-042518-0520-99](https://www.symantec.com/security-center/writeup/2004-042518-0520-99)] also uses this port.<br>Some Apple applications use this port as well: Apple Remote Desktop 2.0 or later (Observe/Control feature), Screen Sharing (Mac OS X 10.5 or later)<br>RealVNC 4.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of connections to port 5900.  
References: [[CVE-2004-1750](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1750)], [[BID-11048](http://www.securityfocus.com/bid/11048)]<br>W32.Gangbot [[Symantec-2007-012219-2952-99](https://www.symantec.com/security-center/writeup/2007-012219-2952-99)] (2007.01.22) - a worm that opens a back door and connects to an IRC server. It spreads by searching for vulnerable SQL servers and by sending an HTML link to available contacts on instant messenger programs. It also spreads by exploiting the Microsoft Internet Explorer Vector Markup Language Buffer Overflow Vulnerability [[BID-20096](http://www.securityfocus.com/bid/20096)] and RealVNC Remote Authentication Bypass Vulnerability [[BID-17978](http://www.securityfocus.com/bid/17978)].<br>Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.  
References: [[CVE-2012-4429](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4429)]<br>Vino could allow a remote attacker to bypass security restrictions, caused by an error in vino-preferences dialog box when providing information on network accessibility. By sending a specially-crafted UPnP request to TCP port 5900, an attacker could exploit this vulnerability to bypass security restrictions to scan internal hosts or proxy Internet traffic and gain unauthorized access to the vulnerable application.  
References: [[XFDB-82881](https://exchange.xforce.ibmcloud.com/vulnerabilities/82881)], [[CVE-2011-1164](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1164)]<br>EchoVNC Viewer is vulnerable to a denial of service, caused by an error when allocating heap buffer size. By connecting to a malicious server, a remote attacker could exploit this vulnerability using a malformed request to TCP port 5900 to cause the application to crash.  
References: [[BID-61545](http://www.securityfocus.com/bid/61545)], [[XFDB-86113](https://exchange.xforce.ibmcloud.com/vulnerabilities/86113)]<br>A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions >= V3.0 _with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (V2.4.X_with_ Siemens Healthineers Informatics products), RAPIDPoint 500 systems (All versions =< V2.3 _with_ Siemens Healthineers Informatics products), RAPIDPoint 400 systems (All versions _with_ Siemens Healthineers Informatics products). A factory account with hardcoded password might allow attackers access to the device over port 5900/tcp. Successful exploitation requires no user interaction or privileges and impacts the confidentiality, integrity, and availability of the affected device. At the time of advisory publication, no public exploitation of this security vulnerability is known. Siemens Healthineers confirms the security vulnerability and provides mitigations to resolve the security issue.  
References: [[CVE-2018-4846](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-4846)]<br>Siemens SINUMERIK Controllers could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow. By sending specially crafted network requests to TCP Port 5900, an attacker could exploit this vulnerability to execute arbitrary code on the system with elevated privileges.  
References: [[CVE-2018-11458](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11458)], [[XFDB-154197](https://exchange.xforce.ibmcloud.com/vulnerabilities/154197)], [[BID-106185](http://www.securityfocus.com/bid/106185)]<br>Remote Framebuffer (TCP/UDP) [[RFC6143](http://tools.ietf.org/html/rfc6143)] (IANA official) | 0.8 |  |
| 6001 | udp |  | X11 - used between an X client and server over the network (official) | 1 |  |
| 8000<br>- clickable [http://website](http://website):8000 | tcp | trojans | Commonly used as an alternate HTTP port. Some firewalls use it for HTTP web administration. Also commonly used for internet radio streams using Nicecast/Icecast/Shoutcast/Winamp audio streaming.<br>Applications that use this port:  
PFSense  
VmWare VMotion  
Nortel Firewall User Authentication  
Barracuda Web Administration  
AWS Local DynamoDB  
Dell OpenManage (remote management for Dell Servers)  
MediaBank  
JRun Management Console  
Splunk  
Django Dev Server  
Chef service "opscode-erchef" uses 8000/TCP to handle Chef server API requests  
HIKVISION iVMS software uses 8000 port for connect clients to PCNVR server  
Seafile Windows Server uses the following TCP ports: 8000 (seahub web interface), 8082 (seafile server), 10001 (ccnet), 12001 (seaf-server).  
X-Lite  
Verint Vid-Center [vid-center.exe], Windows enterprise network DVR application<br>Fortinet FortiGate uses the following ports (in addition to standard ports 53, 80, 443):  
514 tcp - FortiAP logging and reporting  
541 tcp, 542 tcp - FortiGuard management  
703 tcp/udp. 730 udp - FortiGate heartbeat  
1000 tcp, 1003 tcp - policy override keepalive  
1700 tcp - FortiAuthenticator RADIUS disconnect  
5246 udp - FortiAP-S event logs  
8000, 8001 tcp - FortiClient SSO mobility agent  
8008, 8010 tcp - policy override authentication  
8013 tcp - FortiClient v.5.4  
8014 tcp - Forticlient v.6  
8890 tcp - AV/IPS updates, management, firmware  
9443 udp - AV/IPS  
9582 tcp - FortiGuard Cloud App DB ([flow.fortinet.net](http://flow.fortinet.net))<br>Splunk (big data analysis software) uses the following ports by default:  
514 - network input port  
8000 - web port (clients accessing the Splunk search page)  
8080 - index replication port  
8089 - management port (splunkd, aslo used by deployment server)  
9997 - indexing port (web interface)  
9998 - SSL port<br>Malware using this port:  
W32.Gaobot.CEZ [[Symantec-2005-012609-1021-99](https://www.symantec.com/security-center/writeup/2005-012609-1021-99)] (01.25.2005) - Worm with backdoor capabilities. Spreads trough exploiting various vulnerabilities (ports 80, 135, 445). Blocks access to security-related websites and terminates some processes. Connects to an IRC server and listens on port 8000.<br>W32.Spybot.OGX [[Symantec-2005-050217-0724-99](https://www.symantec.com/security-center/writeup/2005-050217-0724-99)] (2005.05.02) - network-aware worm with distributed denial of service and backdoor capabilities. Opens a backdoor by connecting to an IRC server on port 8000/tcp.<br>W32.Mytob.JW@mm [[Symantec-2005-100312-4423-99](https://www.symantec.com/security-center/writeup/2005-100312-4423-99)] (2005.10.04) - a mass-mailing worm with backdoor capabilities that lowers security settings on the compromised computer. Opens a backdoor and listens for remote commands on port 8000/tcp. Also uses port 10027/tcp to download a copy of the worm.<br>JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a long .mp3 URI to TCP port 8000.  
References: [[CVE-2007-4911](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4911)] [[BID-25660](http://www.securityfocus.com/bid/25660)]<br>Gordano NTMail 6.0.3c allows a remote attacker to create a denial of service via a long (>= 255 characters) URL request to port 8000 or port 9000.  
References: [[CVE-2001-0585](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0585)] [[BID-2494](http://www.securityfocus.com/bid/2494)]<br>Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message Dispatcher on TCP port 8000.  
References: [[CVE-2015-2281](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2281)]<br>Port is also IANA registered for iRDMI. | 1 |  |
| 8008<br>- clickable [https://website](http://website):8008 | tcp | Fortinet | Citrix common ICA/HDX HTML5 access to applications and virtual desktops.  
Apple iCal service also uses this port.<br>Fortinet FortiGate uses the following ports (in addition to standard ports 53, 80, 443):  
514 tcp - FortiAP logging and reporting  
541 tcp, 542 tcp - FortiGuard management  
703 tcp/udp. 730 udp - FortiGate heartbeat  
1000 tcp, 1003 tcp - policy override keepalive  
1700 tcp - FortiAuthenticator RADIUS disconnect  
5246 udp - FortiAP-S event logs  
8000, 8001 tcp - FortiClient SSO mobility agent  
8008, 8010 tcp - policy override authentication  
8013 tcp - FortiClient v.5.4  
8014 tcp - Forticlient v.6  
8890 tcp - AV/IPS updates, management, firmware  
9443 udp - AV/IPS  
9582 tcp - FortiGuard Cloud App DB ([flow.fortinet.net](http://flow.fortinet.net))<br>Backdoor.Haxdoor.E [[Symantec-2005-080212-3505-99](https://www.symantec.com/security-center/writeup/2005-080212-3505-99)] (2005.08.01) - trojan that opens a backdoor on the compromised computer, logs keystrokes, steals passwords and drops rootkits that run in safe mode. Opens a backdoor on one or more of the following ports: 7080/tcp, 8008/tcp, or 16661/tcp.<br>njRAT remote access malware - default port is 1177, may also use ports 8008 and 8521. | 0.55 |  |
| 8080<br>- clickable [http://website](http://website):8080 | tcp | http | Common alternative HTTP port used for web traffic. See also TCP ports 80,81,8443. It can also be used for HTTP Web Proxies. Some broadband routers run a web server on port 8080 for remote management. WAN Administration can (and should, in most cases) be disabled using routers web-based administration interface.<br>Ubiquiti UniFi Controller uses these ports:  
8080 tcp - http port for UAP to inform controller  
8443 tcp - https port for controller GUI/API  
8880 tcp - http portal redirect port (may also use ports 8881, 8882)  
8843 tcp - https portal redirect port  
3478 udp - STUN port (should be open at firewall)<br>Splunk (big data analysis software) uses the following ports by default:  
514 - network input port  
8000 - web port (clients accessing the Splunk search page)  
8080 - index replication port  
8089 - management port (splunkd, aslo used by deployment server)  
9997 - indexing port (web interface)  
9998 - SSL port<br>Rainmachine smart sprinkler controllers use ports 80, 8080 and 18080.<br>Microsoft Lync server uses these ports:  
444, 445, 448, 881, 5041, 5060 - 5087, 8404 TCP  
80, 135, 443, 4443, 8060, 8061, 8080 TCP - standard ports and HTTP(s) traffic  
1434 UDP - SQL  
49152-57500 TCP/UDP - media ports<br>Kaspersky Security Center uses these ports:  
8060, 8061 TCP, 15000, 15001 UDP - installation and update packages  
8080 TCP - web console  
13000 TCP/UDP - server port  
13111, 17000, 17100 TCP, 15111 UDP - KSN proxy server  
13291, 13292, 13294, 13295, 13299, 14000, 19170 TCP - client device management<br>If you're not running web services, keep in mind that some trojans also use these ports:  
Reverse WWW Tunnel Backdoor - remote access/tunneling software coded in Perl, uses ports 80, 3128, 8080. Works on Unix, Linux, Solaris, AIX and OpenBSD.  
RingZero (a.k.a. Ring0, Trojan.PSW.Ring, RingZero.gen, Ring) - uses ports 80, 3128, 8080. Affects Windows 9x.  
Screen Cutter (a.k.a. Backdoor.Screencut) - uses ports 80, 8080.  
W32.Mydoom.B@mm [[Symantec-2004-012816-3647-99](https://www.symantec.com/security-center/writeup/2004-012816-3647-99)] (2004.01.28) - mass-mailing worm that opens a backdoor into the system. The backdoor makes use of TCP ports 80, 1080, 3128, 8080, and 10080.<br>W32.Spybot.OFN [[Symantec-2005-042917-1039-99](https://www.symantec.com/security-center/writeup/2005-042917-1039-99)] (2005.04.29) - network-aware worm with DDoS and backdoor capabilities. Spreads through network shares and exploiting multiple vulnerabilities. It ay be downloaded by W32.Kelvir [[Symantec-2005-041414-2221-99](https://www.symantec.com/security-center/writeup/2005-041414-2221-99)] variants. Opens a backdoor on port 8080/tcp. Also exploits vulnerabilities on ports 445 and 1433.<br>W32.Zotob.C@mm [[Symantec-2005-081516-4417-99](https://www.symantec.com/security-center/writeup/2005-081516-4417-99)] (2005.08.16) - a mass-mailing worm that opens a backdoor and exploits the MS Plug and Play Buffer Overflow vulnerability (MS Security Bulletin [[MS05-039](http://technet.microsoft.com/en-us/security/bulletin/MS05-039)]) on port 445/tcp. It connects to IRC servers and listens for remote commands on port 8080/tcp. It also opens an FTP server on port 33333/tcp.  
Note: Same ports are used by the W32.Zotob.A [[Symantec-2005-081415-0646-99](https://www.symantec.com/security-center/writeup/2005-081415-0646-99)] and W32.Zotob.B [[Symantec-2005-081415-0741-99](https://www.symantec.com/security-center/writeup/2005-081415-0741-99)]variants of the worm as well.<br>W32.Zotob.E [[Symantec-2005-081615-4443-99](https://www.symantec.com/security-center/writeup/2005-081615-4443-99)] (2005.08.16) - a worm that opens a backdoor and exploits the MS Plug and Play Buffer Overflow vulnerability (MS Security Bulletin [[MS05-039](http://technet.microsoft.com/en-us/security/bulletin/MS05-039)]) on port 445/tcp. It runs and spreads using all current Windows versions, but only infects Windows 2000.  
The worm connects to IRC servers and listens for remote commands on port 8080/tcp. It opens port 69/udp to initiate TFTP transfers. It also opens a backdoor on remote compromised computers on port 8594/tcp.  
Backdoor.Naninf.D [[Symantec-2006-020115-0317-99](https://www.symantec.com/security-center/writeup/2006-020115-0317-99)] (2006.02.01)  
Backdoor.Naninf.C [[Symantec-2006-013111-4821-99](https://www.symantec.com/security-center/writeup/2006-013111-4821-99)] (2006.01.31)<br>W32.Rinbot.A [[Symantec-2007-021615-1555-99](https://www.symantec.com/security-center/writeup/2007-021615-1555-99)] (2007.03.02) - a worm that opens a back door, copies itself to IPC shares, connects to an IRC server, and awaits commands on port 8080/tcp. See Also [[CVE-2002-1123](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1123)], [[CVE-2006-2630](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2630)], [[CVE-2006-3439](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3439)]<br>Android.Acnetdoor [[Symantec-2012-051611-4258-99](https://www.symantec.com/security-center/writeup/2012-051611-4258-99)] (2012.05.16) - opens a backdoor on Android devices<br>Feodo/Geodo (a.k.a. Cridex or Bugat) trojan used to commit e-banking fraud uses ports 8080 tcp and 7779/tcp to run a nginx proxy and communicate with the botnet C&C server.<br>A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could perform a persistent Cross-Site Scripting (XSS) attack, potentially resulting in obtaining administrative permissions.  
References: [[CVE-2017-2683](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2683)], [[BID-96455](http://www.securityfocus.com/bid/96455)]<br>The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.  
References: [[CVE-2017-2682](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2682)], [[BID-96458](http://www.securityfocus.com/bid/96458)]<br>FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or api/bg_system or txtapi/bg_system) query string on TCP port 8080, as demonstrated by an api/system?calc URI. This can also be exploited via CSRF. Alternatively, the default password of works for the freeswitch account can sometimes be used.  
References: [[CVE-2018-19911](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19911)] | 1 |  |
| 8443<br>- clickable [https://website](http://website):8443 | tcp | HTTPS | Common alternative HTTPS port.<br>PCSync HTTPS (SSL), SW Soft Plesk Control Panel, Apache Tomcat SSL, iCal service (SSL), Cisco WaaS Central Manager (SSL administration port), Promise WebPAM SSL<br>Ubiquiti UniFi Controller uses these ports:  
8080 tcp - http port for UAP to inform controller  
8443 tcp - https port for controller GUI/API  
8880 tcp - http portal redirect port (may also use ports 8881, 8882)  
8843 tcp - https portal redirect port  
3478 udp - STUN port (should be open at firewall)<br>Cisco WaaS Central Manager standard SSL administration port.<br>German Health Getwork (aka Gesundheitskarte) "Konnektor" uses ports 8443 and 9443.<br>Tanium Server, Client and Appliance use these TCP ports: 80, 443, 8443, 17472, 17477<br>Symantec Endpoint Protection Manager could allow a remote attacker to obtain sensitive information, caused by an XML External Entity Injection (XXE) error within the SAP XML parser when processing XML data. By sending a specially-crafted request to TCP port 8443, an attacker could exploit this vulnerability to read arbitrary files and obtain sensitive information.  
References: [[XFDB-91102](https://exchange.xforce.ibmcloud.com/vulnerabilities/91102)], [[EDB-31853](https://www.exploit-db.com/exploits/31853/)], [[EDB-31917](https://www.exploit-db.com/exploits/31917/)]<br>Symantec Backup Exec System Recovery Manager could allow a remote attacker to upload arbitrary files, caused by an error in the FileUpload Class running on the Symantec LiveState Apache Tomcat server. A remote attacker could exploit this vulnerability using an HTTP POST request over port 8443 (TCP) to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable system with SYSTEM privileges.  
References: [[XFDB-40260](https://exchange.xforce.ibmcloud.com/vulnerabilities/40260)]<br>VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious actor could access /cfg diagnostic endpoints without authentication.  
References: [[CVE-2021-22002](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22002)] | 1 |  |
| 8888<br>- clickable [http://website](http://website):8888 | tcp | althttpd | Used by some applications as an alt http port.<br>Applications using this port:  
AirDroid  
Freenet nodes  
FortiNet's enterprise UTM client software  
MAMP on macOS default Apache port  
GNUmp3d HTTP music streaming and Web interface  
LoLo Catcher HTTP web interface ([www.optiform.com](http://www.optiform.com))  
SimpleCam v2.0  
Sun Answerbook HTTP server  
Winpower Manager for UPS (internal server)  
HyperVM HTTPS  
D2GS Admin Console Telnet administration console for D2GS servers (Diablo 2)  
Earthland Relams 2 Server (AU1_2)  
NewsEDGE server (IANA official)<br>Games using port 8888:  
Evil Islands  
Heroes of Might and Magic 5  
Splinter Cell (Chaos Theory, Double Agent, Pandora Tomorrow)  
Ultima Online<br>Vulnerabilities/Malware:  
Napster  
W32.Axatak  
Dark IRC (trojan)  
W32.Axatak [[Symantec-2002-082217-5638-99](https://www.symantec.com/security-center/writeup/2002-082217-5638-99)] - password stealing virus with remote access trojan capabilities. Affects all current Windows versions, uses ports 8888 and 8889.<br>Autodesk VRED Professional 2014 contains an unauthenticated remote code execution vulnerability. Autodesk VRED Professional 2014 contains an integrated web server that binds to port tcp/8888 which is accessible remotely. It has been reported that this web server gives access to a Python API which provides users with a vast amount of libraries which could allow an attacker to execute operating system commands. Through this API, Python code can be executed on the target system, the output is returned in the web server response. By importing the Python "os" library, arbitrary operating system commands can be executed on the target system with the privileges of the user running VRED Professional 2014.  
References: [[CVE-2014-2967](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2967)]<br>An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" client application listening on 127.0.0.1 port 8888 can send a malicious payload causing a buffer overflow condition. This will result in code execution, as demonstrated by a TCP reverse shell, or a crash. NOTE: this vulnerability exists because of an incomplete fix for [CVE-2018-6892](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6892).  
References: [[CVE-2018-7886](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7886)], [[EDB-44470](https://www.exploit-db.com/exploits/44470/)]<br>A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.  
References: [[CVE-2019-7678](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7678)]<br>XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.  
References: [[CVE-2019-7677](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7677)]<br>A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.  
References: [[CVE-2019-7676](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7676)] | 1 |  |
| 10000<br>- clickable [http://website](http://website):10000 | tcp | multiple | Applications that use this port:  
Webmin - web-based system administration tool, BackupExec, Ericsson Account Manager (avim).  
The Matrix Online, Everquest Online Adventures, BitTornado, Viatalk, Dungeon Fighter Online (TCP/UDP), FIFA Manager 10 (TCP/UDP)  
QuickTime Streaming Server 4 also uses ports 10000-20000 (TCP).<br>Dumaru.Y [[Symantec-2004-012316-2557-99](https://www.symantec.com/security-center/writeup/2004-012316-2557-99)] (2004.01.23) - multi-threaded, mass mailing worm that opens a backdoor, runs a keylogger and attempts to steal personal information. Opens ports 2283/tcp and 10000/tcp.<br>Other trojans that use this port: Oracle, TCP Door, XHX, OpwinTRojan<br>The default configuration of the New Atlanta BlueDragon administrative interface in MediaCAST 8 and earlier enables external TCP connections to port 10000, instead of connections only from 127.0.0.1, which makes it easier for remote attackers to have an unspecified impact via a TCP session.  
References: [[CVE-2011-2077](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2077)]<br>Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a buffer overflow in observiced.exe that allows remote attackers to execute arbitrary code via vectors related to a "reverse lookup of connections" to TCP port 10000.  
References: [[CVE-2010-0072](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0072)]<br>The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pairing values and a crafted request to port 10000.  
References: [[CVE-2014-8515](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8515)], [[XFDB-99764](https://exchange.xforce.ibmcloud.com/vulnerabilities/99764)]<br>By using port 10000 TCP in VERITAS Backup Exec Remote Agent, a remote attacker may be able to gain access to, and retrieve arbitrary files from a target system.  
References: [[CVE-2005-2611](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2611)], [[BID-14551](http://www.securityfocus.com/bid/14551)]<br>Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain privileged file system access or change configuration settings.  
References: [[CVE-2017-2689](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2689)], [[BID-97170](http://www.securityfocus.com/bid/97170)]<br>Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port 10000/TCP which is prone to reflected Cross-Site Scripting attacks if an unsuspecting user is induced to click on a malicious link.  
References: [[CVE-2017-2687](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2687)], [[BID-97170](http://www.securityfocus.com/bid/97170)]<br>Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interface at port 10000/TCP and access sensitive information.  
References: [[CVE-2017-2686](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2686)], [[BID-97170](http://www.securityfocus.com/bid/97170)]<br>An exploitable buffer overflow vulnerability exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. A specially crafted request on port 10000 can cause a buffer overflow resulting in overwriting arbitrary data.  
References: [[CVE-2017-2876](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2876)], [[CVE-2017-2875](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2875)]<br>The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtain access via an HTTP session on port 10000, as demonstrated by reading the modem password (which is 1234), or reconfiguring "party mode" or "vacation mode."  
References: [[CVE-2019-9484](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9484)] | 0.95 |  |
| 32768 | tcp,udp | first-os-ports | first ports typically used for outgoing connections by some Linux distros like Red Hat: see /etc/rc.d/init.d/network and /proc/sys/net/ipv4/ip_local_port_range<br>Nascar 4 (UDP), Joint Operations Typhoon Rising (UDP) use port 32768.<br>Hacker's Paradise trojan also uses port 32768 (TCP). | 1 |  |
|  | tcp,udp | applications | As the first port in the dynamic/private range (49152-65535), this port is commonly used by applications that utilize a dynamic/random/configurable port.<br>Many embedded Linux based systems (i.e. home routers, remote management devices, IP cameras) have UPnP enabled, broadcasting their kernel version and hardware architecture over port 49152.<br>Some P2P torernt clients often use this port: uTorrent, Azureus/Vuze, etc.<br>Older IPMI firmware versions reveal cleartext login credentials over UDP port 49152.<br>Apple AirPlay dynamic mirroring TCP port.<br>YotaPhone 2 opens port 49152.<br>Apple Xsan Filesystem Access uses the dynamic/private range 49152-65535.  
Xsan (Apple's storage area network, or clustered filesystem for macOS) uses these ports:  
311 TCP - Xsan secure server administration (server app, xsan server admin, workgroup manager, server monitor)  
312 TCP - Xsan administration  
626 UDP - server serial number registration (Xsan, Mac OS X Server v10.3 – v10.6)  
49152-65535 TCP - Xsan Filesystem Access<br>Microsoft Lync server uses these ports:  
444, 445, 448, 881, 5041, 5060 - 5087, 8404 TCP  
80, 135, 443, 4443, 8060, 8061, 8080 TCP - standard ports and HTTP(s) traffic  
1434 UDP - SQL  
49152-57500 TCP/UDP - media ports<br>The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, configures an unauthenticated proxy service on WAN TCP port 49152, which allows remote attackers to establish arbitrary TCP connections to intranet hosts by sending \x2a\xce\x01 followed by other predictable values.  
References: [[CVE-2017-14117](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14117)], [[BID-100585](http://www.securityfocus.com/bid/100585)] | 1 |  |
|  | tcp | Xsan | Xsan Filesystem Access | 1 |  |
|  | 49152<br>- clickable [https://website](http://website):49152 |  |  |  |  |
|  |  |  |  |  | 49154 |
| **9200**<br>- clickable [https://website](http://website):9200/_aliases?pretty=true | tcp,udp | Elastic-Search | Elasticsearch listens on ports 9200 and 9300 TCP<br>Starlink gRPC uses ports 9200 and 9201 TCP<br>Some Lexmark printers open port 9200 TCP/UDP<br>WapServ Lite, WapServ Pro and WapServ Enterprise are vulnerable to a denial of service. By sending specific byte values over port 9200 or port 9201, a remote attacker can cause the gateway to consume large amounts of memory resources, prevent the gateway from starting, or cause the gateway to crash.  
References: [[BID-8472](http://www.securityfocus.com/bid/8472)], [[XFDB-13011](https://exchange.xforce.ibmcloud.com/vulnerabilities/13011)]<br>File Replication Pro could allow a remote attacker to execute arbitrary commands on the system, caused by an error in the ExecCommand function. By viewing configuration.xml, an attacker could exploit this vulnerability to send specially-crafted packet to port 9200 to execute arbitrary commands on the system.  
References: [[XFDB-110638](https://exchange.xforce.ibmcloud.com/vulnerabilities/110638)]<br>WAP Connectionless Wireless Session Protocol (TCP/UDP) [WAP Forum] (IANA official) | Fail |  |
| **27017** | tcp | MongoDB | IANA registered for: Mongo database system | Fail |  |
| **1521** | tcp | Oracle-DB | Oracle database default listener. Oracle Database Management uses the following ports:  
1521 TCP - Oracle SQL Net Listener and Data Guard  
1832 TCP - Oracle Enterprise Management Agent HTTP (range 1830-1849)  
49896 TCP - Oracle Clusterware (CRS daemon)<br>Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.  
References: [[CVE-2002-0509](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0509)], [[BID-4391](http://www.securityfocus.com/bid/4391)]<br>Port is also IANA registered for nCube License Manager | Fail |  |
| **5432** | tcp | PortgreSQL | ARD 2.0 Database, PostgreSQL Database<br>Xerox WorkCentre and WorkCentre Pro do not block the postgres port (5432/tcp), which has unknown impact and remote attack vectors, probably related to unauthorized connections to a PostgreSQL daemon.  
References: [[CVE-2006-6469](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6469)] | Fail |  |
</details>

**Hijack-Check (%7)**

Calculation - even if there is 1 hijackable subdomain  the test fails and the infrastructure part for the organization gets (-7%)

**SMTP open Mail Relay (13%)**

Calculation - even if there is 1 Open-Mail relay the test fails and the infrastructure part for the organization gets (-13%)

**DNS-Scan (5%)**

Calculation - If the zone transfer is possible - reduce 5% 

### **Application (15%)**

**WAF Scan (10%**) - calculation - every website which is not behind a WAF will fail the test 

Calculation number of websites behind a WAF / number of total Websites

100 websites 55 behind WAF - 55/100 = 55*0.1 = 5.5

**Web Tech (5%)**-  If a web application asset  is not behind a WAF and has a technology with a CVE - fail the test  (- 5%)

### **Data-Leak 10%**

The calculation, if there is a data leak for the organization, fail until reviewed and suppressed(-10%) 

### **Cloud 15%**

If there is an exposed cloud bucket that contains data that do not picture. Fail the test meaning (- 15%)

Calculation -** **if exposed bucket (exposed >0) and not (Content of bucket ==pictures)  = (-15%)

### **Employees 20%**

Assuming that only 5% of leaked credentials can be reused 

Calculation

20% == 100% of employees 

(number of leaked last 3 months) /  (by number of employees) * 2 = 13 / 100 * 2 = 26

+

(Number of leaked between 3 months to 6 months) /( the number of employees) *1.5 = 14 / 100 *1.5 = 21

+

(Number of leaked all time before 6 months)  / (number of employees) * 0.13 = 40  *0.13 = 5.2

100 - 26 -21 -5.2 = 47.8 

47.8 * 0.2 = 9.56%


<u>**Cynergy's Exposure Risk methodology:**</u>

Cynergy has 3 types (Passive, Active, and Validated) of exposure risk calculations which are based on an "outside-in" approach. The risk is modeled based on FAIR Factor Analysis of Information Risk

- **Passive Risk Scoring** is calculated based on information that is collected and enumerated from various sources without using intrusive tools which may affect the organization and its environment.
- **Active Risk scoring** is done using various active Vulnerability Assessments which are carried out continuously on the identified organization assets and the organization’s digital environment
- **Validated Risk Scoring** is done by active validation of the risk based on the exploitation of the identified vulnerabilities, to provide a risk score that is based on a high percentage of attack surface coverage and optimized with a low amount of false positives.

**Not like other cybersecurity risk score providers** who measure the cybersecurity performance of the organization. Cynergy is looking at the **exposure risk**. The exposure risk is based on sources of data collected from a reconnaissance covering the most predominant attack vectors, which are leveraged by attackers.  
Cloud, Applications, Data-leak, Infrastructure, Network, Technologies, SaaS and 3rd parties, Privacy and Employee risks.   
Each identified organization asset is being inventoried and passes contextualization and threat modeling to assess the impact of a singular asset on the overall security risk based on STAMP (System-Theoretic  
Accident Model and Process), which searches for individual component failures by identifying missing requirements, configurations, design mistakes problematic interactions between components, and human errors. shifting focus away from pinpointing problems one-by-one and instead dynamically identifying dysfunctional interactions and behaviors within the system as a whole.

To correctly threat model exposure, Cynergy uses ML to contextualize and classify the exposure, to define what is its criticality to the organization’s business continuity.  
Resulting in an accurate threat model per each identified asset in the organization.  
The weights of the risk from each vector are being standardized based on **Benford's law**, to assess the correctness of the ML models over time.

![image](media://7480a1b8-9e6f-442b-8b64-824fc52df2c3)


The exposure risk is being calculated based on quantitive threat modeling of the exposed, Web and Mobile applications UI, APIs, Javascript external communication and the data transfer to 3rd parties, Features, Data, Cloud instances and buckets, Infrastructure assets, employee and organization data leakage, DNS and SMTP misconfigurations.  
The risk weights between the discovered assets are continuously checked via the two-way Analysis of variance (ANOVA) statistic model for consistency.

![image](media://9f359d79-269c-4e4f-9b5c-4e2dfb73b88d)


And the overall score is being standardized using the multivariate analysis of variance (MANOVA) statistic model.