Common Services, Threats & Attacks: What Each Open Port Means

Every open port is a decision someone made — and most of those decisions were made without thinking about what an attacker sees. This Cover6 Community session maps the services that run on almost every network to the threats that target them, so that when you read a scan, you’re not just seeing numbers: you’re seeing a threat profile.

Use this post as your read-ahead, then come back to it as a quick reference.

YouTube thumbnailYouTube icon

Read a scan like a threat actor

An attacker reading your scan results isn’t impressed by a long list — they’re looking for the one service that’s weak, outdated, or misconfigured. The session uses scanme.nmap.org, a target Nmap provides specifically so people can practice legally, and a basic scan to surface what’s open:

nmap -T4 -sV -Pn --top-ports 15 --open scanme.nmap.org

The -sV service-version flag is the important part: knowing a port is open tells you a little, but knowing what version is running tells you whether there’s a known attack for it. Pair the scan with banner grabbing — using netcat or curl to make a service announce itself — and you often get the software and version straight away.

Scan only targets you own or ones, like scanme.nmap.org, that explicitly permit it.

The ports to know by heart

A handful of services show up on nearly every network, and each carries its own threat profile:

PortServiceWhat it’s forWhat the attacker looks for
21FTPFile transferAnonymous login, cleartext credentials, old vulnerable versions
22SSHRemote adminWeak or reused passwords, outdated versions, exposed keys
25SMTPEmailOpen relays, user enumeration
53DNSName resolutionZone transfers, information leakage
80HTTPWeb (cleartext)The whole web-app attack surface; traffic readable on the wire
443HTTPSWeb (encrypted)Web-app flaws, weak TLS configuration
445SMBWindows file sharingOpen shares, old protocol versions, a top target for ransomware
3306MySQLDatabaseDefault credentials, direct exposure to the internet
3389RDPRemote desktopBrute force, exposure to the internet — a favorite entry point

The pattern across all of them: an attacker reads the version, asks whether a known attack exists, and if the service shouldn’t be exposed at all, that’s a finding before they even touch it.

Each service has an attack path

Mapping the service to the attack is the whole game:

  • Cleartext protocols (FTP, HTTP, Telnet) leak whatever they carry — credentials, data — to anyone watching the wire. The first question is always “why isn’t this encrypted?”
  • Remote-access services (SSH, RDP) are brute-force magnets when passwords are weak and they’re exposed to the internet.
  • File-sharing (SMB) is where a lot of real-world damage happens — open shares, old protocol versions, lateral movement, ransomware.
  • Web (HTTP/HTTPS) is an entire discipline of its own: the service is a door into the application behind it.

Knowing the attack path for a service is also knowing the fix: encrypt it, restrict it, patch it, or take it off the internet.

Practice reading services on a lab you own

The way this clicks is to scan a target, read the services, and work out the attack path yourself. First Shell is the free Cover6 lab that runs in your browser — you get an authorized target, so you can scan it, read the open services, and prove which ones are actually weak.

👉 Start here, free: https://www.cover6solutions.com/product/cover6-first-shell-free-access/

Prefer the defender’s seat? First Watch gives you a live Splunk lab and your first SOC shift, free, where those same services show up as things to monitor and harden: https://www.cover6solutions.com/product/cover6-first-watch-free-access/

Where this path leads

Knowing services and their threats is foundational on both the SOC Analyst and Penetration Tester paths on Chrysalus. Build your free profile and add your service analysis as a project.

Watch the replay

We ran this live in the Cover6 Community — a legal scan of scanme.nmap.org, the ports to know by heart, and the attack path behind each service. Planning to attend a future meetup? Use this post as your read-ahead, and catch the replay above.

The 6 — Free Newsletter

Job openings, new courses, free workshops, and what’s working in cyber careers right now — straight to your inbox.

Free forever. Confirm by email, unsubscribe any time. We never share your address.

Shopping Cart
Scroll to Top