TCP/IP Protocol Ports List: (Commonly Used Protocols) Port #7 -> ICMP - "Internet Control Message Protocol" (Packet information - Used w/ pings) Port #7 -> Echo - (One way communication - Used w/ pings - "Half Duplex" - Used w/ ICMP) Port #20 -> FTP - "File Transfer Protocol" (Data channel) Port #21 -> FTP - "File Transfer Protocol" (Control channel) Port #22 -> SSH - "Secure Shell" (Secure remote connections) Port #23 -> Telnet - "Terminal Emulation" (Secure remote connections) Port #25 -> SMTP - "Simple Mail Transfer Protocol" (E-mail) Port #49 -> TACACS - "Terminal Access Controller Access Control System" (Secure remote Unix connections) Port #50 -> ESP - "Encapsulation Security Payload" (IPSec) Port #51 -> AH - "Authentication Header" (IPSec) Port #53 -> DNS - "Domain Name System" (or Service or Server) Port #67 -> DHCP - "Dynamic Host Configuration Protocol" (Dynamic IP assign) Port #68 -> DHCP - "Dynamic Host Configuration Protocol" (Dynamic IP assign) Port #69 -> TFTP - "Trivial File Transfer Protocol" (FTP w/ no security) Port #79 -> Finger - (User Information Retrieval Protocol - Unix) Port #80 -> HTTP - "HyperText Transfer Protocol" (Used w/ Internet) Port #88 -> Kerberos (Secure network file transfer) Port #109 -> POP v2 - "Post Office Protocol" (E-mail) Port #110 -> POP v3 - "Post Office Protocol" (E-mail) Port #111 -> DCOM - "Distributed Component Object Model" (Remote connections, like RPC) Port #119 -> NNTP - "Network News Transfer Protocol" (Retrieve USENET messages) Port #123 -> NTP - "Network Time Protocol" (Time synchronization) Port #135 - RPC - "Remote Procedure Call" (Remote connections, like Telnet) Port #137 -> NetBIOS - "Network Basic Input Output System" (NetBIOS transport layer) Port #138 -> NetBIOS - "Network Basic Input Output System" (NetBIOS transport layer) Port #139 -> NetBIOS SMB - "Network Basic Input Output System Server Message Block" (NetBIOS transport layer) Port #143 -> IMAP - "Internet Message Access Protocol" (E-mail - POP w/ additional features) Port #161 -> SNMP - "Simple Network Management Protocol" (Network management) Port #162 -> SNMP Trap - "Simple Network Management Protocol" Trap (SNMP event notification) Port #389 -> LDAP - "Lightweight Directory Access Protocol" (Information directory access) Port #443 -> HTTPS (S-HTTP) - "Secure HyperText Transfer Protocol" (Secure internet) Port #443 -> SSL - "Secure Sockets Layer" (Secure internet data transfer) Port #445 -> SMB w/ IP - "Server Message Block" w/ "Internet Protocol" (Used w/ NetBIOS and Samba) Port #636 -> LDAP w/ TLS - "Lightweight Directory Access Protocol" w/ "Transport Layer Security" (Secure information directory access) Port #689 -> LDAP w/ SSL - "Lightweight Directory Access Protocol" w/ "Secure Sockets Layer" (Secure information directory access) Port #1234 -> SubSeven - (Commonly Used "Backdoor Trojan Horse" Port - Unauthorized Access) Port #12345 -> NetBus - (Commonly Used "Backdoor Trojan Horse" Port - Unauthorized Access) Port #1701 -> L2F/L2TP - "Layer Two Tunneling Protocol" (Secure VPN) Port #1723 -> PPTP - "Point-to-Point Tunneling Protocol" (VPN remote access) Port #1812 -> RADIUS - "Remote Authentication Dial-In User Service" (Dial-Up ISP authentication) Port #3128 -> Squid Proxy - (Internet Proxy Application) Port #31337 -> BackOrifice - (Commonly Used "Backdoor Trojan Horse" Port - Unauthorized Access) Port #3389 -> MRP - "Microsoft Remote Desktop" (Remote tech support) Port #6711 -> SubSeven - (Commonly Used "Backdoor Trojan Horse" Port - Unauthorized Access) Port #8080 -> HTTP - "HyperText Transfer Protocol" (Used w/ Internet)