Skip to main content

Port Details

Port
23
Transport
TCP
Service
Telnet
IANA service name
telnet
Range
System port (0-1023)
Related ports
222323

Security Exposure

Telnet sends all data, including login credentials, in plaintext, so captured traffic reveals passwords and session contents (UK Government Cyber Unit). CISA alert TA16-288A describes Mirai infecting devices that still use default usernames and passwords and advises monitoring 23/TCP and 2323/TCP for takeover attempts. MITRE ATT&CK also lists Telnet among services targeted by password guessing.

Hardening

  • +Disable the Telnet service and remove inbound firewall and port forwarding rules for port 23.
  • +Replace Telnet with SSH for remote administration.
  • +Change default device passwords to strong, unique passwords, as CISA advises for IoT devices.
  • +Where Telnet cannot be removed yet, allow it only from a trusted management network.

Monitoring

Alert on inbound connection attempts to 23/TCP and 2323/TCP, as CISA recommends for spotting IoT takeover attempts. Internal scans should also flag any host or device that still runs a Telnet listener.

Tools for Auditing and Monitoring Telnet

Cowrie

Open Source
Honeypot & Deception Tools

Medium to high interaction SSH and Telnet honeypot that records attacker sessions.

LicenseBSD-3-Clause
PlatformLinux

OpenCanary

Open Source
Honeypot & Deception Tools

Open source multi-protocol daemon honeypot from the Thinkst Canary project.

LicenseBSD-3-Clause
PlatformLinux, macOS

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

Is Telnet on port 23 secure?→

No. Telnet runs on TCP port 23 and sends data, including credentials, in plaintext (UK Government Cyber Unit). SSH is the standard replacement.

Why do attackers scan port 23?→

Botnets such as Mirai look for devices that accept Telnet logins with default credentials, according to CISA alert TA16-288A. Infected devices are then used in DDoS attacks.

Is Telnet TCP or UDP?→

Telnet runs over TCP. IANA lists port 23 for both TCP and UDP, but Telnet sessions are TCP connections.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 23 is not guaranteed to be Telnet. Exploited-in-the-wild data from the CISA KEV catalog (CC0).