Open port scanning is the process of systematically probing a server or network device to find out which of its network ports respond to the outside world. The same technique serves both as an attacker's reconnaissance step and as an administrator's defensive tool. This article covers how port scanning works, what the different port states mean, the services you are most likely to encounter, and the legal framework in Turkey.
What Is Open Port Scanning?
Every network service running on a computer listens for incoming connections on a specific number called a port. A web server uses ports 80 and 443, a mail server uses 25, and SSH for remote access uses port 22. Port scanning is the method of sending connection attempts (probes) to a target in sequence and, based on the responses, determining which ports are open, that is, actively being listened to by a service.
A rough analogy is knocking on each door of a building and noting which ones open. Ports operate on top of the IP address layer: you first reach the target's IP address, then probe the ports on that IP. For the bigger picture of how networks fit together, see our Internet and Networking Basics guide.
Ports and Protocols in Brief
A port number is a 16-bit value, which means there are 65,536 possible ports, numbered 0 through 65535. Ports are usually referenced alongside one of two transport protocols: the connection-oriented and reliable TCP, or the connectionless and faster UDP. The same number can be used separately for TCP and UDP; DNS, for example, can run on both 53/TCP and 53/UDP.
IANA divides the port range into three groups. This split gives a rough hint about what kind of service a port is likely to belong to:
| Range | Name | Typical use |
|---|---|---|
| 0 – 1023 | Well-known | Standard services such as HTTP, HTTPS, SSH, DNS |
| 1024 – 49151 | Registered | Ports assigned to applications (e.g. databases) |
| 49152 – 65535 | Dynamic / private | Ephemeral client connections |
How Does a Port Scan Work?
A scanner sends packets to the target ports and infers each port's state from the reply. On the TCP side, whether the three-way handshake (SYN, SYN-ACK, ACK) completes is the deciding factor. The most common scanning techniques are:
- TCP connect scan: Uses the operating system's connect call to complete a full handshake. It is reliable but more likely to leave traces on the target.
- SYN (half-open) scan: Only a SYN is sent; if a SYN-ACK comes back, the port is considered open and the connection is torn down with an RST. Because the connection is never completed, it is quieter.
- UDP scan: Since UDP is connectionless, the absence of a reply often means 'open or filtered', which makes UDP scanning slower and more ambiguous than TCP.
- FIN, NULL, and Xmas scans: Advanced techniques that use unusual flag combinations to try to slip past certain firewalls.
The most widely used open-source tool for this is nmap; high-speed scanners like masscan and online port-check services are also common.
Port States: Open, Closed, Filtered
Scan results are not a simple open-or-closed binary. When firewalls sit in the path, ambiguous states appear as well:
| State | Meaning |
|---|---|
| Open | A live service is listening on the port and accepting connections. |
| Closed | The port is reachable, but no service is listening behind it. |
| Filtered | A firewall is dropping the packet, so the port's state cannot be determined. |
Common Ports and Their Services
The ports below are among the most frequently seen on the internet. Recognizing them helps you interpret scan results and shut down unnecessary exposed services:
| Port | Protocol | Service |
|---|---|---|
| 22 | TCP | SSH (secure remote access) |
| 25 | TCP | SMTP (email sending) |
| 53 | TCP/UDP | DNS (name resolution) |
| 80 | TCP | HTTP (web) |
| 443 | TCP | HTTPS (encrypted web) |
| 3306 | TCP | MySQL database |
| 3389 | TCP | RDP (remote desktop) |
Why It Matters for Security
Open ports are a system's outward-facing surface; every open port is a potential entry point for an attacker. Attacks often begin with reconnaissance: the attacker finds which ports are open and which services run behind them, then tries known vulnerabilities. That is exactly why the same scan becomes a self-audit tool on the defensive side.
Scanning your own server from the outside shows you what is actually exposed. If you serve from a fixed address, remember that your static IP surface stays the same over time, which makes regular checks even more important.
The Legal Framework in Turkey
Scanning your own systems, or running a penetration test on a system for which you hold written authorization, is legitimate. Scanning systems that belong to others without permission, and especially continuing that scan into an attempt at unauthorized access or disruption, carries legal risk.
In Turkey, acts against information systems are addressed in the section of the Turkish Penal Code (Law No. 5237) that governs cybercrime; unlawfully entering an information system and hindering or damaging its operation are defined as offences there. Administrative processes such as access blocking are instead carried out under Law No. 5651.
Practical Tips for Administrators
- Scan your servers from the outside regularly and investigate any unexpected open ports.
- Restrict access to management services such as SSH, RDP, and databases to specific addresses with a firewall.
- Turn off services you do not use; every open port is a maintenance and security burden.
- Changing standard ports where appropriate can reduce noise, but it is not a security measure on its own.
- Only scan systems that belong to you or for which you have written permission.