Port 3389 — RDP

Port
3389
Transport
TCP
Service
Remote Desktop Protocol

What port 3389 is for

Windows graphical remote access: the full desktop, keyboard and mouse of a remote machine delivered over the network. It is how most Windows servers are administered and how a great deal of remote work reaches office desktops.

Security considerations

The single most common entry point for ransomware. Exposed RDP is found within minutes and attacked continuously, and credential stuffing against it succeeds often enough to sustain an industry. Put it behind a VPN or a gateway, always with multi-factor authentication.

Worth knowing. If you take one thing from this list: do not expose 3389 to the internet.

If a scan shows port 3389 open

Close it immediately and check the security event log for logins you cannot account for. Exposed RDP is the most common ransomware entry point there is, and a compromise here is usually a full-network compromise.

Check it yourself

The port scanner will tell you whether 3389 is reachable on a host you control. Checking from outside your own network matters: a port can be open on the machine and still be blocked at the firewall, and it is the view from the internet that decides whether anyone else can reach it.

Only scan hosts you own or have permission to test.

Related ports

« Every port in the reference