Open port scanning is the process of systematically probing a server or network device to find out which of its network ports respond to the outside world. The same technique serves both as an attacker's reconnaissance step and as an administrator's defensive tool. This article covers how port scanning works, what the different port states mean, the services you are most likely to encounter, and the legal framework in Turkey.

What Is Open Port Scanning?

Every network service running on a computer listens for incoming connections on a specific number called a port. A web server uses ports 80 and 443, a mail server uses 25, and SSH for remote access uses port 22. Port scanning is the method of sending connection attempts (probes) to a target in sequence and, based on the responses, determining which ports are open, that is, actively being listened to by a service.

A rough analogy is knocking on each door of a building and noting which ones open. Ports operate on top of the IP address layer: you first reach the target's IP address, then probe the ports on that IP. For the bigger picture of how networks fit together, see our Internet and Networking Basics guide.

Ports and Protocols in Brief

A port number is a 16-bit value, which means there are 65,536 possible ports, numbered 0 through 65535. Ports are usually referenced alongside one of two transport protocols: the connection-oriented and reliable TCP, or the connectionless and faster UDP. The same number can be used separately for TCP and UDP; DNS, for example, can run on both 53/TCP and 53/UDP.

IANA divides the port range into three groups. This split gives a rough hint about what kind of service a port is likely to belong to:

RangeNameTypical use
0 – 1023Well-knownStandard services such as HTTP, HTTPS, SSH, DNS
1024 – 49151RegisteredPorts assigned to applications (e.g. databases)
49152 – 65535Dynamic / privateEphemeral client connections

How Does a Port Scan Work?

A scanner sends packets to the target ports and infers each port's state from the reply. On the TCP side, whether the three-way handshake (SYN, SYN-ACK, ACK) completes is the deciding factor. The most common scanning techniques are:

  • TCP connect scan: Uses the operating system's connect call to complete a full handshake. It is reliable but more likely to leave traces on the target.
  • SYN (half-open) scan: Only a SYN is sent; if a SYN-ACK comes back, the port is considered open and the connection is torn down with an RST. Because the connection is never completed, it is quieter.
  • UDP scan: Since UDP is connectionless, the absence of a reply often means 'open or filtered', which makes UDP scanning slower and more ambiguous than TCP.
  • FIN, NULL, and Xmas scans: Advanced techniques that use unusual flag combinations to try to slip past certain firewalls.

The most widely used open-source tool for this is nmap; high-speed scanners like masscan and online port-check services are also common.

Port States: Open, Closed, Filtered

Scan results are not a simple open-or-closed binary. When firewalls sit in the path, ambiguous states appear as well:

StateMeaning
OpenA live service is listening on the port and accepting connections.
ClosedThe port is reachable, but no service is listening behind it.
FilteredA firewall is dropping the packet, so the port's state cannot be determined.

Common Ports and Their Services

The ports below are among the most frequently seen on the internet. Recognizing them helps you interpret scan results and shut down unnecessary exposed services:

PortProtocolService
22TCPSSH (secure remote access)
25TCPSMTP (email sending)
53TCP/UDPDNS (name resolution)
80TCPHTTP (web)
443TCPHTTPS (encrypted web)
3306TCPMySQL database
3389TCPRDP (remote desktop)

Why It Matters for Security

Open ports are a system's outward-facing surface; every open port is a potential entry point for an attacker. Attacks often begin with reconnaissance: the attacker finds which ports are open and which services run behind them, then tries known vulnerabilities. That is exactly why the same scan becomes a self-audit tool on the defensive side.

Scanning your own server from the outside shows you what is actually exposed. If you serve from a fixed address, remember that your static IP surface stays the same over time, which makes regular checks even more important.

Practical Tips for Administrators

  • Scan your servers from the outside regularly and investigate any unexpected open ports.
  • Restrict access to management services such as SSH, RDP, and databases to specific addresses with a firewall.
  • Turn off services you do not use; every open port is a maintenance and security burden.
  • Changing standard ports where appropriate can reduce noise, but it is not a security measure on its own.
  • Only scan systems that belong to you or for which you have written permission.