Skip to content

We use analytics cookies to understand how the site is used and to improve it. Privacy policy

SubAnalyzer

Every port SubAnalyzer scans and what it means

A guide to the 58 TCP ports SubAnalyzer checks: what usually runs on each open port and which exposed services deserve attention

Updated (9 min read)

An open port means a service at that address is accepting network connections. When SubAnalyzer reports one, the service was reachable from the internet during the scan. It may still require authentication before anyone can use it.

Public HTTPS on a website is expected. A database, desktop session or container management API deserves closer attention. The question is whether the service needs public access and how that access is protected.

SubAnalyzer checks 58 TCP ports on every scan. The five categories below match the colored port chips in your results. Labels describe common uses and come from the port number. They do not identify the software or version running there. As the IANA port registry explains, traffic on a registered port can belong to a different service.

The 58 TCP ports every scan checks, grouped into the five categories and colors the scan page uses for its port chips.

Web ports

These 22 ports cover public websites, alternative web listeners, development servers and management interfaces. A public application can legitimately use any of them. An administration page needs tighter access controls, even when its connection is encrypted.

Websites and alternative web ports

PortScan labelTypical use and what to check
80HTTPOrdinary web traffic, often redirected to HTTPS. Check that sensitive pages and logins require encryption.
443HTTPSEncrypted web traffic. Expected on a public website, but also used by private applications and administration pages.
8180008081808288809080HTTP AltAlternative HTTP listeners for applications, proxies and development environments. Identify the application and its intended audience.
8080HTTP ProxyOften a proxy or ordinary HTTP application. If it is a proxy, check that strangers cannot use it to relay traffic.
44438443944310443HTTPS AltAlternative encrypted web listeners. Check whether they expose a public application or an internal management interface.

Port 8443 is not dangerous by itself. An authenticated production application there may be intentional. A forgotten administration page on the same port is a different finding. The application and its access controls determine the risk.

Development servers and management interfaces

PortScan labelTypical use and why it matters
3000HTTP AltCommon Node.js development applications or Grafana. Check for an unintended development server or exposed dashboard.
5000HTTP AltOften Flask or a container registry. Flask's development server is unsuitable for production use.
70017002WebLogicWebLogic application and administration traffic. Apply security updates and restrict administrative access.
8161ActiveMQThe ActiveMQ web console. Restrict access and replace default credentials.
8888HTTP AltOften Jupyter or a proxy console. Unprotected Jupyter access can let someone run code on the machine.
9000HTTP AltOften SonarQube or MinIO's storage API. Check who can access project information or stored objects.
9090HTTP AltOften Prometheus. Anyone who reaches it can read every stored time series, and Prometheus says its HTTP endpoints should not be exposed to the internet.
10000WebminServer administration. A compromised Webmin installation can give an attacker root-level control.

Defaults vary. Jupyter enables token authentication by default, while ActiveMQ documents default console credentials that should be changed. Check the deployed configuration before concluding that an interface is unprotected.

Database ports

These six ports cover databases, search indexes and caches. They usually belong on private networks or behind rules that allow only the applications and administrators that need them. A public listener increases exposure even when a password is required.

PortScan labelTypical use and exposure risk
3306MySQLA relational database. Review allowed clients, account permissions and encryption.
5432PostgreSQLA relational database. Review network access and authentication rules, especially rules that trust clients without a password.
6379RedisAn in-memory data store. Unrestricted access can let someone read, change or delete application data.
9200ElasticThe Elasticsearch REST API. An unprotected instance can expose entire indexes and allow data changes or deletion.
11211MemcachedAn application cache. Public access can expose cached data or let outsiders alter it.
27017MongoDBA document database. Missing access controls can expose collections and allow destructive changes.

Redis has no password configured in a basic default setup, but its protected mode can reject remote commands. Elasticsearch automatically enables security on eligible new installations. Neither an open 6379 nor an open 9200 establishes that data is accessible without authentication. Verify the actual settings using the Redis security guide and Elasticsearch security documentation.

Memcached's documentation explicitly warns against public exposure. Its known traffic amplification problem involves UDP, so a TCP finding on 11211 does not establish that amplification is possible. See the Memcached configuration guide and UDP advisory.

Email ports

These seven ports support sending and retrieving email. Public reachability is normal when you operate a mail server. Unexpected mail services on a development or application host are worth investigating.

PortScan labelTypical use
25SMTPReceiving and relaying email between mail servers. An open port does not mean the server is an open relay.
110POP3Retrieving email. Encryption can be negotiated after connecting.
143IMAPAccessing and managing mailboxes. Encryption can be negotiated with STARTTLS.
465SMTPSClient email submission with TLS encryption from the start of the connection.
587SubmissionClient email submission, commonly using STARTTLS to enable encryption.
993IMAPSIMAP with TLS encryption from the start of the connection.
995POP3SPOP3 with TLS encryption from the start of the connection.

Require encryption for mailbox access and client submission, and authenticate users before accepting their outgoing mail. A service scan does not verify those policies. The email TLS standard explains the distinction between encryption at connection time and an upgrade through STARTTLS.

Remote access ports

These five ports can provide a shell, a desktop or access to a graphical session. Review them promptly when they appear on an unexpected host.

PortScan labelTypical use and exposure risk
22SSHEncrypted remote administration. Public access can be intentional, but restrict accounts, use strong authentication and keep the server updated.
23TelnetObsolete remote administration that ordinarily sends credentials and session data without encryption. Disable public access and replace it with SSH.
3389RDPWindows remote desktop. Public listeners are frequent targets for brute-force attacks. Restrict access through a protected remote-access service.
5900VNCDesktop viewing and control. Weak passwords or missing authentication can give outsiders control of the session.
6001X11Conventionally X11 display :1. A client the X server trusts can read other windows and capture input. Keep direct access restricted.

CISA recommends limiting exposed remote desktop services, using multifactor authentication and closing unused access.

Infrastructure ports

These 18 ports cover file sharing, network services, container management, dashboards and messaging. Some are expected on public infrastructure. Others expose services normally intended for trusted clients.

File sharing and network services

PortScan labelTypical use and what to check
21FTPLegacy file transfer. Standard FTP sends passwords in clear text, although servers can support TLS. Check whether it is still needed.
53DNSDNS over TCP. Expected on a public authoritative nameserver. Restrict recursive queries to intended clients.
111RPCThe Unix RPC portmapper, used to locate services including older NFS services. Restrict it to trusted clients.
113IdentA legacy service that can return the user associated with a connection. It may disclose account information.
139NetBIOSOlder Windows file sharing over NetBIOS sessions. Keep it behind restricted network access.
199SMUXA legacy connection between subagents and an SNMP monitoring agent. It normally belongs on a trusted network.
445SMBWindows file sharing. Public exposure creates unnecessary opportunities to attack file shares and their servers.
548AFPOlder Apple file sharing, largely replaced by SMB. Restrict access to trusted clients.
1025No name shownThe start of the dynamic port range used by older Windows systems, including RPC services. Identify the listener before drawing conclusions.
1720H.323Call signaling for voice and video conferencing. Public access may be intentional. Confirm that it matches your conferencing setup.
1723PPTPAn outdated VPN protocol with known security weaknesses. Replace it with a modern VPN.

Microsoft documents 1025 at the start of the older Windows dynamic port range. It does not reliably identify the listener. Microsoft also recommends blocking inbound SMB from the internet and replacing PPTP.

Container management

PortScan labelTypical use and exposure risk
2376Docker TLSThe Docker daemon API over TLS. If the daemon runs as root, unauthorized API access can give an attacker control of the host.
6443KubernetesThe Kubernetes API server. Weak authentication or excessive permissions can expose secrets and allow changes to workloads.
10250KubeletThe kubelet API on a cluster node. Anonymous access combined with permissive authorization can allow commands to run inside containers.

Encryption alone does not establish that clients are authorized. Check client authentication and permissions using Docker's daemon protection guide and Kubernetes' guidance on API access controls and kubelet authentication and authorization.

Dashboards and messaging

PortScan labelTypical use and exposure risk
5601KibanaA web interface for Elasticsearch data. An unprotected dashboard can expose logs and other sensitive records.
5672AMQPMessaging, typically RabbitMQ. Review authentication, permissions and transport encryption.
9091No name shownOften Prometheus Pushgateway or Transmission's web interface. Identify the application and restrict its write or management access.
9092KafkaUsually a Kafka broker. Weak access controls can let unauthorized clients read or publish messages.

Prometheus Pushgateway and Transmission both use 9091 by default. The number alone cannot distinguish a metrics endpoint from a torrent client's management interface.

How to read your scan results

Each subdomain lists its open ports as colored chips, such as 443 HTTPS and 22 SSH. The Services tile counts distinct open port numbers across the scan. If 20 subdomains all expose 80 and 443, the tile counts two distinct ports.

Use the Services filter to find subdomains with one or several selected ports open.

Each subdomain lists its open ports as chips. The Services tile counts the distinct ports across the scan, 9 here, and the Services filter narrows the list to subdomains with the ports you pick.

For subdomains with an open web port, SubAnalyzer captures a screenshot and page title. TLS checks also read certificates on all five HTTPS ports: 443, 4443, 8443, 9443 and 10443. Names on those certificates can reveal additional subdomains, which are then scanned too.

How SubAnalyzer confirms an open port

The service scan starts with a fast pass that sends the opening packet of a TCP connection. A reply alone is insufficient because firewalls and protective services can answer for ports with no application behind them. Before showing a result, SubAnalyzer requires a completed TLS handshake on its HTTPS ports, a real HTTP response on its designated HTTP ports, or, on other ports, a connection that holds without being reset. If an address answers a control check on port 2, its fast-pass results are discarded. Ports 80 and 443 are always tried.

Both hosts answer the first packet, so the fast pass alone would call both ports open. The confirmation tells them apart: the web server completes a TLS handshake and presents its certificate, while the SYN proxy resets the connection as soon as data arrives.

The scan checks up to eight public IPv4 addresses per host, with no more than about 25 probes per second to any one address. It scans TCP only. UDP services, including SNMP on 161/udp, are outside its scope. IPv6 addresses are recorded but are not scanned for services. SubAnalyzer never logs in, identifies software versions or tests for vulnerabilities.

For the full process, read how our subdomain scanner works.

What to do about an unexpected port

  1. Identify the service and its owner. Check which application is listening and why it needs network access. Use the port label as a starting point.
  2. Restrict unnecessary public access. Update firewall or cloud network rules, bind the service to a private interface, or disable it if it is unused. Check dependencies before making changes.
  3. Review access controls. Require appropriate authentication, limit permissions, enable encryption and install security updates. If sensitive data may have been exposed, investigate access logs and affected credentials.
  4. Re-scan and monitor. Verify the change from outside your network, then watch for the port returning.

This follows CISA's internet exposure reduction guidance: identify exposed services, decide which need public access and protect those that remain.

SubAnalyzer can re-scan a monitored domain daily, weekly or monthly and send one email when something changes. Newly opened or closed ports are among the changes it reports. One monitored domain is free, and paid plans monitor up to 10.

Scan your domain to see which of these services are reachable across your subdomains.

Sources

← All articles