What Is a Port Scanner?
A port scanner sends connection requests to TCP ports on a host and records which ones respond. Open ports indicate active services. Check your server: Port Scanner
Which Ports Should Be Open?
| Port | Service | Public? |
|---|---|---|
| 80 | HTTP | Yes (web servers) |
| 443 | HTTPS | Yes (web servers) |
| 22 | SSH | Whitelist IPs only |
| 3306 | MySQL | Never public |
| 5432 | PostgreSQL | Never public |
| 6379 | Redis | Never public |
| 27017 | MongoDB | Never public |
| 3389 | RDP | Never public |
How a Port Scan Actually Works
A basic TCP scan attempts to complete the first two steps of the standard three-way handshake: it sends a SYN packet and watches the response. A SYN-ACK reply means the port is open and listening; a RST (reset) packet means it's closed; no response at all usually means a firewall is silently dropping the packet rather than actively rejecting it. This is why a well-configured firewall matters more than just "closing" a port — a dropped connection gives an attacker less information than an actively refused one, since they can't easily tell whether anything is even running there.
What Actually Happened With Exposed MongoDB Instances
The MongoDB ransom wave wasn't hypothetical — starting in late 2016 and escalating through 2017, attackers ran automated scans across the internet, found tens of thousands of MongoDB instances left open with no authentication, wiped their contents, and left a ransom note demanding payment for data that, in most cases, they'd never actually kept a copy of. It remains one of the clearest real-world demonstrations of why "default config with no auth, bound to 0.0.0.0" is a genuinely dangerous default, not just a theoretical risk.
Most Dangerous Open Ports
Port 3306 - MySQL
An open MySQL port is one of the most common data breach causes. Attackers constantly scan for exposed databases. MySQL should only be accessible from localhost or your app server private IP.
Port 27017 - MongoDB
Thousands of MongoDB databases have been wiped and ransomed because the default config binds to all interfaces. Always bind to 127.0.0.1 unless you specifically need remote access.
Port 6379 - Redis
Redis has no authentication by default. An open Redis port lets anyone read all cached data including sessions. Bind to localhost and set AUTH passwords.
How to Close Dangerous Ports
UFW (Ubuntu)
ufw deny 3306 | ufw deny 27017 | ufw deny 6379
AWS Security Groups
Edit your security group to remove any rules allowing 0.0.0.0/0 on database ports. Restrict SSH to your IP only.
Related Tools
- SSL Checker - Check SSL alongside port security
- WHOIS Lookup - Identify domain and hosting details
- IP Blacklist Checker - Check if your server IP is blacklisted

