Concept · 6 min read
What is a port?
If an address finds the machine, what finds the program?
A port is a 16-bit delivery number that lets one IP address host many services. It says 'hand this to that listener', nothing more.
Socket = address + port
Transport protocols identify endpoints by a pair: address plus port. A TCP connection is fully described by five values — source address, source port, destination address, destination port and protocol. That is why 'is port 443 open?' is ambiguous unless you add 'from where'.
Numbering
- 0–1023: well-known ports, reserved for system services (22 SSH, 25 SMTP, 80 HTTP, 443 HTTPS, 53 DNS)
- 1024–49151: registered ports used by applications
- 49152–65535: ephemeral ports, usually the client side of a connection
- Port numbers are the same in TCP and UDP but unrelated: 53/udp and 53/tcp can be different programs.
What a scan can and cannot prove
A listener answering does not prove what program is behind it, and a filtered port does not prove a service is absent — only that your probe got no usable answer from this position.
bash
ss -ltnp
# LISTEN 0 128 0.0.0.0:22 users:(("sshd",pid=641))
nmap -p 22,80,443 192.0.2.10
# 22/tcp open ssh | 80/tcp filtered http | 443/tcp closed httpsCheck your understanding
Answer before expanding. If you cannot explain it in one sentence, the section above needs a re-read.
Why can a port be open internally and closed from your laptop?Q1
Firewall rules are directional. Reachability is a property of the path, not the port.
You found 8080/tcp 'open'. What is the next command?Q2
Read the banner or the response: `nc -nv host 8080` or `curl -sv http://host:8080/` — then decide whether it is in scope to probe further.
Where this shows up
Tools in the directory whose commands assume this knowledge.