Skip to main content

Port Details

Port
6000
Transport
TCP
Service
X11
IANA service name
x11
Range
User port (1024-49151)

Security Exposure

X11 traffic is not encrypted, so a reachable X server allows eavesdropping on the session, as a Red Hat knowledge base article notes. The xhost host-based control trusts entire hosts, and the Xserver -ac option disables host-based access control and enables access by any host. Vulnerability scanning tools flag a listening X11 server, which is the scenario the Red Hat article addresses.

Hardening

  • +Start the X server with -nolisten tcp so it does not accept network connections.
  • +Use the cookie-based or private-key authorization mechanisms in Xsecurity instead of host-based access.
  • +Avoid the -ac option, which the Xserver manual says enables access by any host.
  • +Block TCP 6000 to 6063 at the firewall.

Monitoring

Alert on any host listening on TCP 6000 to 6063 and on inbound connections to that range. The X server -audit option can log connection rejections and accepted connections.

Tools for Auditing and Monitoring X11

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

OPENVAS

Free / Commercial
Vulnerability Scanning

Full-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.

LicenseGPL-2.0-only (C scanner); GPL-2.0-or-later WITH OpenSSL-exception (Rust)
PlatformLinux

Nessus

Commercial
Vulnerability Scanning

Tenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.

LicenseProprietary
PlatformLinux, Windows, Web

Frequently Asked Questions

Why is port 6000 open on a Linux server?→

An X server that accepts TCP connections listens on port 6000 for display :0. A Red Hat knowledge base article addresses a vulnerability scanner warning about Xorg listening on 6000.

How is X11 TCP listening disabled?→

The Xserver manual documents the -nolisten tcp option, which disables TCP/IP connections.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 6000 is not guaranteed to be X11. Exploited-in-the-wild data from the CISA KEV catalog (CC0).