Port 1524Ingreslock

Port 1524 is commonly associated with the Ingreslock backdoor trojan related to the Ingres database software. Originally designed for internal database communication, over time, it has been widely abused by attackers to gain unauthorized access to systems, making it a known security concern. Both TCP and UDP protocols can be used on this port, increasing its attack surface and necessitating vigilant network monitoring and filtering..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
4/10

caution

lookups
7,484

rank 680 of 993 · top 68%

Technical Details

what runs on :1524

Port 1524 was initially associated with Ingres, an enterprise relational database management system. Typically, Ingres used this port internally to enable remote management functions and database communication. It sometimes became exposed externally due to misconfigurations, creating risks for database environments relying on network interactions.

Historically, this port gained notoriety because malicious actors exploited it via the Ingreslock backdoor trojan. The trojan would listen on port 1524, enabling unauthorized remote shell access. Its presence was typically the result of post-compromise activity, where attackers installed it after initial exploitation to maintain persistence without raising suspicion.

Due to its connection with remote management and known abuses, security practitioners view any open port 1524 as suspicious unless explicitly required and controlled. Modern usage of this port for legitimate Ingres databases often avoids internet exposure, instead residing behind strong access controls and internal network segmentation.

Security Information

exposure of :1524

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

security averages 3.8 across 216 ports — this one sits 0.2 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • Presence of the Ingreslock trojan, a known backdoor providing shell access
  • Weak firewall configurations that leave port 1524 exposed externally
  • Exploitation via lateral movement after initial compromise
  • Lack of access controls on internal database services

Common Mitigations:

  • Strictly block inbound and outbound traffic on port 1524 at perimeter and host-based firewalls unless explicitly required
  • Use network intrusion detection systems (NIDS) to identify suspicious traffic or shell activity via this port
  • Regularly scan hosts for unauthorized listeners on port 1524
  • Harden authentication and disable unnecessary services in Ingres deployments
  • Segment internal networks to minimize lateral movement risk
  • Conduct regular malware and rootkit detection scans

the 8 most looked-up other ports in security — 216 ports carry that label.

risk mix of the 8 listed

  • caution100%

3 of 8 encrypted