Avatar of Mike Paradis
Mike Paradis

asked on 

Well known ports and optimal ports scanning range

When security port scanning a very large number of machines, what is the optimal range of ports to scan?
While the well known port range is something like 1-1024, there are many services which exist in the 4 digit range.
Is there a secondary 'well known' range which isn't as large the as full 64K range which takes much too long.
SecurityNetwork ManagementNetwork Analysis

Avatar of undefined
Last Comment
Technical Engeneer
Avatar of Predrag Jovic
Predrag Jovic
Flag of Poland image

You have a list on Wiki:
List of TCP and UDP port numbers
That should help.
SOLUTION
Avatar of Qlemo
Qlemo
Flag of Germany image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of Mike Paradis
Mike Paradis

ASKER

@Predrag Jovic - Lists don't help, that is why I posted the question. I've looked plenty on the net before asking.

@Qlemo - Yes, we have permission of course, this isn't about hacking.
I know there is no second well known ports range and what I mean is, what is the next most optimal range to scan without scanning the full 64K which takes too long.

This is what I'm trying to find out.
Avatar of arnold
arnold
Flag of United States of America image

As the prior what is the purpose of your scan will dictate whether the 1-1024 are sufficient or whether the entire scope shoukd be scanned when you are searching for a system that might have been configured or compromised.
1-1024 were the common, these days there are other well known ports including 1433,3306,3389,8080,3128,1812/1814/1645/1646.......

/etc/services on Linux, iana maintains, publishes a list of known ports and their designated usage .........


You could use one scan to determine the underlying os, then SCan port ranges specific for that OS.
Money auto include/enable software firewalls denying icmp........
Avatar of Predrag Jovic
Predrag Jovic
Flag of Poland image

The thing is that there is no other "Well known port list", additionally ... The other ports often can be used by different vendors, and even ports that are on the wiki list - might still be security risk and still should be checked are ports really in use.
Avatar of Mike Paradis
Mike Paradis

ASKER

Come on guys, I've explained that I know there is no second list of well known ports. I'm using that as a term only since what I am asking about doesn't exist. No need to keep showing me where I can get lists of ports, I already know those things.

I am asking specifically, what would be the optimum port range to scan if I wanted to scan beyond 1024 but not the full 64K ports.
As I also said, it seems many services are in the 4 digit range so I guess I'm answering my own question here, 1-4096 for example might be a good balance.
Avatar of Predrag Jovic
Predrag Jovic
Flag of Poland image

Known range typically used for VOIP:

RTP: UDP ports 16384-32767
CUCM: UDP ports 24576-32767
ASKER CERTIFIED SOLUTION
Avatar of arnold
arnold
Flag of United States of America image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
Avatar of Qlemo
Qlemo
Flag of Germany image

It has been said, the purpose dicates a good choice of port ranges. But yes, if you stay below 4k you will cover most "well-known" services like databases, remote maintenance, web services ... But you still will need to add some single ports like 8080, 8085, 8088 for web proxies, VMs, and more.
People also like to add a digit for obfuscation, like 10080 instead of 80, but applying that for checking the range 1-4095 doesn't really help to reduce the port count ...
Avatar of masnrock
masnrock
Flag of United States of America image

You're asking too broad a question. Arnold basically has pointed why it cannot be answered based on what you provided. If your point overall is just to know whether unauthorized ports are open then you would have to scan the entire range. If you want to know whether there are software misconfigurations, then you could probably use ranges based on the OS, software and servers in place.
Avatar of Mike Paradis
Mike Paradis

ASKER

Yes, it is a broad question but asked in the best way I could think of. I kept getting replies about where to look for well known ports and other ports lists which is not what I was asking about.

Basically, I am asking experts what they think, in terms of covering a fair range that could find potential problems, in an optimized way, meaning, not scanning all 64K ports. Of course, I understand that there is no miracle answer since someone could run a web server on any port, 80, 8080, 64000, etc.

I think scanning to a 4000 range would be a good start and depending on the results, if there is an anomaly, ports we know should not be open, then scan deeper.

I'm not quite sure how to award this but I'll go by whom ever came closest first.
You can use Network Service Scanner and Open TCP Port Scanner feature in NetCrunch Tools to scan your network (any range) for 70 most well-known services (SSH, FTP, Web, Mail, SQL, NTP, SMTP, TIME, WhoIs, FTPS and so on). The software is free.
Security
Security

Security is the protection of information systems from theft or damage to the hardware, the software, and the information on them, as well as from disruption or misdirection of the services they provide. The main goal of security is protecting assets, and an asset is anything of value and worthy of protection. Information Security is a discipline of protecting information assets from threats through safeguards to achieve the objectives of confidentiality, integrity, and availability or CIA for short. On the other hand, disclosure, alteration, and disruption (DAD) compromise the security objectives.

32K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo