Skip to main content

Port Details

Port
69
Transport
UDP
Service
TFTP
IANA service name
tftp
Range
System port (0-1023)

Security Exposure

RFC 1350 states that TFTP includes no login or access control mechanisms, so anyone who can reach the server can request any file it makes available. A server that permits writes lets outsiders upload or overwrite files. CISA alert TA14-017A also lists TFTP as a UDP protocol abused for reflection attacks, with a bandwidth amplification factor of 60.

Hardening

  • +Disable TFTP when it is not in active use and block UDP 69 at the internet edge.
  • +Serve only files that are meant to be public and disallow writes, as RFC 1350 describes for typical installations.
  • +Run the TFTP daemon with minimal file system rights, confined to a dedicated directory.
  • +Limit TFTP access to the provisioning or management network that needs it.

Monitoring

Log each TFTP read and write request with the file name and client address. Alert on requests from outside the provisioning network and on any write attempt to a read-only server.

Tools for Auditing and Monitoring TFTP

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Suricata

Open Source
Network Monitoring Tools

High-speed network intrusion detection, prevention, and security monitoring engine with deep protocol parsing capabilities.

LicenseGPL-2.0-only
PlatformLinux, FreeBSD, macOS, Windows

Frequently Asked Questions

Is TFTP TCP or UDP?→

TFTP runs over UDP. IANA lists port 69 for both TCP and UDP, but RFC 1350 implements TFTP on top of UDP.

Does TFTP use authentication?→

No. RFC 1350 states that TFTP has no login or access control, so access must be limited through file permissions and network filtering.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 69 is not guaranteed to be TFTP. Exploited-in-the-wild data from the CISA KEV catalog (CC0).