Port 1080: SOCKS proxy protocol
TCP 1080 is the conventional port for SOCKS proxy servers, which relay TCP connections and, in SOCKS5, UDP traffic through the UDP ASSOCIATE command. RFC 1928 defines SOCKS5 and its authentication methods: none, GSSAPI and username/password. RFC 1928 describes SOCKS as a way for client applications to traverse network firewalls.
Port Details
Security Exposure
A SOCKS server that offers the no-authentication method lets anyone relay traffic through it, which hides the true source of abuse behind the proxy's address. RFC 1929 notes that username/password authentication sends the password in cleartext. The FBI has warned that criminal proxy services install proxies on compromised end-of-life routers to conduct crimes anonymously.
Hardening
- +Bind SOCKS proxies to localhost or internal interfaces unless remote use is required.
- +Disable the no-authentication method and require GSSAPI or username/password over an encrypted tunnel.
- +Restrict allowed client addresses and destination ports on the proxy.
- +Replace end-of-life routers and disable remote administration, as the FBI recommends.
Monitoring
Alert on unexpected listeners on TCP 1080 and on hosts relaying large numbers of outbound connections to many destinations. Review proxy logs for client addresses outside approved ranges.
Tools for Auditing and Monitoring SOCKS
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Frequently Asked Questions
Is SOCKS on port 1080 encrypted?→
No. SOCKS itself does not encrypt traffic, and RFC 1929 notes its username/password method carries the password in cleartext.
Does SOCKS5 support UDP?→
Yes. RFC 1928 defines a UDP ASSOCIATE command, while the client connects to the SOCKS server over TCP, conventionally on port 1080.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 1080 is not guaranteed to be SOCKS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).