What's new

Port 53 Open According to Shodan

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

ericnix

Occasional Visitor
I searched for my IP address on Shodan and was surprised to see that I had an open port (53).

Is this enabled by default for most routers? I don't have a port forward set up for it. Not sure if my router automatically opens it (UniFi Security Gateway-Pro).
 
If you have a dynamic IP, Shodan could be reporting that port 53 was open when someone else had your current IP.

You could use some free online port scanner to confirm that it is open.
 
Sometimes it's the modem that has the port 53/udp port open from the WAN side - have seen this before...
 
Actually the modem would not show because it wont have the public ip address.

Port 53 open on WAN side is bad because it means the router's DNS service is exposed to WAN and people can use your router as a DNS server or potentially feed it DNS replies which could be the wrong addresses. This is serious.
 
Uh... Why?

Not sure why, except for perhaps a misconfiguration on the carrier side of the modem - I've seen it before during scans by request for friends...

It is a bit worrisome as this is a potential security issue in many ways (everything from DDOS via DNS amplification attacks to potential information leakage depending on how things are configured).
 
When I used several port scanners, it didn't show anything open. Maybe Shodan is outdated with someone who had the IP before me?
 

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top