Port 69: Trivial File Transfer Protocol
UDP port 69 is used by the Trivial File Transfer Protocol (TFTP), a very simple file transfer protocol defined in RFC 1350. A client sends its read or write request to port 69, and the transfer then continues between ports chosen by each side. TFTP runs on top of UDP and has no login step.
Port Details
Security Exposure
RFC 1350 states that TFTP includes no login or access control mechanisms, so anyone who can reach the server can request any file it makes available. A server that permits writes lets outsiders upload or overwrite files. CISA alert TA14-017A also lists TFTP as a UDP protocol abused for reflection attacks, with a bandwidth amplification factor of 60.
Hardening
- +Disable TFTP when it is not in active use and block UDP 69 at the internet edge.
- +Serve only files that are meant to be public and disallow writes, as RFC 1350 describes for typical installations.
- +Run the TFTP daemon with minimal file system rights, confined to a dedicated directory.
- +Limit TFTP access to the provisioning or management network that needs it.
Monitoring
Log each TFTP read and write request with the file name and client address. Alert on requests from outside the provisioning network and on any write attempt to a read-only server.
Tools for Auditing and Monitoring TFTP
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Zeek
Open SourceNetwork security monitoring framework that translates raw packet traffic into structured transaction logs and network events.
Suricata
Open SourceHigh-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.
Related Tool Categories
Frequently Asked Questions
Is TFTP TCP or UDP?→
TFTP runs over UDP. IANA lists port 69 for both TCP and UDP, but RFC 1350 implements TFTP on top of UDP.
Does TFTP use authentication?→
No. RFC 1350 states that TFTP has no login or access control, so access must be limited through file permissions and network filtering.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 69 is not guaranteed to be TFTP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).