Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend in with normal network activity, to avoid more detailed inspection. They may use the protocol associated with the port, or a completely different protocol. They may use commonly open ports, such as the examples provided below. * TCP:80 (HTTP) * TCP:443 (HTTPS) * TCP/UDP:53 (DNS) * TCP:1024-4999 (OPC on XP/Win2k3) * TCP:49152-65535 (OPC on Vista and later) * TCP:23 (TELNET) * UDP:161 (SNMP) * TCP:502 (MODBUS) * TCP:102 (S7comm/ISO-TSAP) * TCP:20000 (DNP3) * TCP:44818 (Ethernet/IP)

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Routers
is related to Field I/O
is related to Data Historian
is related to Virtual Private Network (VPN) Server
is related to Programmable Logic Controller (PLC)
is related to Intelligent Electronic Device (IED)
is related to Distributed Control System (DCS) Controller
is related to Firewall
is related to Safety Controller
is related to Workstation
is related to Jump Host
is related to Data Gateway
is related to Human-Machine Interface (HMI)
is related to Programmable Automation Controller (PAC)
is related to Remote Terminal Unit (RTU)
is related to Switch
is related to Application Server
is related to Control Server
is blocked by Human User Authentication
is blocked by Detection of Commonly Used Port
is blocked by Network Intrusion Prevention
is blocked by Network Segmentation
is blocked by Disable or Remove Feature or Program
Impressum Deutsch Englisch