Port 23: Telnet
TCP 23 is the port for Telnet remote terminal. Never on the internet. Telnet is a top target for IoT botnets such as Mirai.
| Service | Telnet remote terminal |
|---|---|
| Protocol | TCP |
| Exposure risk | High: do not expose to the internet |
| Secure alternative | SSH (port 22) |
| Range | Well-known (0–1023): binding needs root/admin on Unix |
What port 23 does
Telnet is the unencrypted predecessor of SSH. It survives on old switches, printers, IoT devices and serial console servers, and is still handy as a raw TCP test client (telnet host port).
Should port 23 be open?
Never on the internet. Telnet is a top target for IoT botnets such as Mirai. Where you can, use SSH (port 22) instead.
Find what's listening on port 23
- Linux:
sudo ss -tulpn | grep :23 - macOS:
sudo lsof -nP -i :23 - Windows:
netstat -ano | findstr :23, then look up the PID in Task Manager.
Open or block it in a firewall
- ufw:
sudo ufw allow 23/tcp(ordeny) - firewalld:
sudo firewall-cmd --add-port=23/tcp --permanent && sudo firewall-cmd --reload - Windows:
New-NetFirewallRule -DisplayName "Port 23" -Direction Inbound -Protocol TCP -LocalPort 23 -Action Allow
Port assignment per the IANA Service Name and Transport Protocol Port Number Registry. Test several ports at once with the port scanner, or any port with the open port checker.
Questions about port 23
What is port 23 used for?
Telnet remote terminal. Telnet is the unencrypted predecessor of SSH. It survives on old switches, printers, IoT devices and serial console servers, and is still handy as a raw TCP test client (telnet host port).
Is port 23 TCP or UDP?
TCP. Telnet uses TCP port 23.
Is it safe to open port 23?
High: do not expose to the internet. Never on the internet. Telnet is a top target for IoT botnets such as Mirai. Secure alternative: SSH (port 22).
How do I check if port 23 is open?
Use the checker on this page: it connects to your host on TCP 23 from the internet. Locally, run
nc -vz host 23 (macOS/Linux) or Test-NetConnection host -Port 23 (PowerShell). To see what is listening on your own machine, run ss -tulpn | grep :23 (Linux) or netstat -ano | findstr :23 (Windows).