Skip to main content

Port Details

Port
5222
Transport
TCP
Service
XMPP
IANA service name
xmpp-client
Range
User port (1024-49151)
Related ports
5269

Security Exposure

XMPP servers that accept client connections from the internet are exposed to password guessing against user accounts and to flaws in the server software. Clients can be downgraded to plaintext if an attacker strips the STARTTLS offer, which RFC 7590 describes. The Openfire XMPP server has a KEV-listed path traversal in its administrative console (CVE-2023-32315).

Hardening

  • +Require STARTTLS on every client stream and refuse plaintext authentication.
  • +Follow RFC 7590 and RFC 7525 guidance on TLS versions and cipher suites.
  • +Enforce strong passwords or SCRAM-based SASL mechanisms for user accounts.
  • +Keep the XMPP server software patched and keep its web administration console off the internet.
  • +Limit 5222 to the user populations that need it when the service is internal.

Monitoring

Track failed SASL authentications per account and per source address, and alert on sessions that complete without TLS.

Tools for Auditing and Monitoring XMPP

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Wireshark

Open Source
Network Monitoring Tools

Network packet analyzer and protocol inspection tool for capturing live traffic and debugging network communications in detail.

LicenseGPL-2.0-or-later
PlatformWindows, macOS, Linux, BSD

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Frequently Asked Questions

What is port 5222 used for?→

Port 5222 is the XMPP client-to-server port. RFC 6120 uses it for client connections and 5269 for server-to-server federation.

Is XMPP on port 5222 encrypted?→

XMPP on 5222 starts in plaintext and upgrades with STARTTLS. RFC 7590 states that TLS support is mandatory for XMPP implementations.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5222 is not guaranteed to be XMPP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).