Port 23: Telnet remote terminal protocol
Port 23 is assigned to Telnet, the remote terminal protocol defined in RFC 854, which gives command-line access to a remote system. CISA alert TA16-288A describes the Mirai botnet scanning the internet for vulnerable IoT devices such as routers and video cameras, and ties that activity to Telnet on 23/TCP.
Port Details
Security Exposure
Telnet sends all data, including login credentials, in plaintext, so captured traffic reveals passwords and session contents (UK Government Cyber Unit). CISA alert TA16-288A describes Mirai infecting devices that still use default usernames and passwords and advises monitoring 23/TCP and 2323/TCP for takeover attempts. MITRE ATT&CK also lists Telnet among services targeted by password guessing.
Hardening
- +Disable the Telnet service and remove inbound firewall and port forwarding rules for port 23.
- +Replace Telnet with SSH for remote administration.
- +Change default device passwords to strong, unique passwords, as CISA advises for IoT devices.
- +Where Telnet cannot be removed yet, allow it only from a trusted management network.
Monitoring
Alert on inbound connection attempts to 23/TCP and 2323/TCP, as CISA recommends for spotting IoT takeover attempts. Internal scans should also flag any host or device that still runs a Telnet listener.
Tools for Auditing and Monitoring Telnet
Cowrie
Open SourceMedium to high interaction SSH and Telnet honeypot that records attacker sessions.
OpenCanary
Open SourceOpen source multi-protocol daemon honeypot from the Thinkst Canary project.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Decoy services, deception platforms, and canary tokens that detect intruders with high-fidelity alerts.
Packet capture tools, protocol analyzers, and network security monitors for traffic visibility.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Frequently Asked Questions
Is Telnet on port 23 secure?→
No. Telnet runs on TCP port 23 and sends data, including credentials, in plaintext (UK Government Cyber Unit). SSH is the standard replacement.
Why do attackers scan port 23?→
Botnets such as Mirai look for devices that accept Telnet logins with default credentials, according to CISA alert TA16-288A. Infected devices are then used in DDoS attacks.
Is Telnet TCP or UDP?→
Telnet runs over TCP. IANA lists port 23 for both TCP and UDP, but Telnet sessions are TCP connections.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 23 is not guaranteed to be Telnet. Exploited-in-the-wild data from the CISA KEV catalog (CC0).