Port 1524Ingreslock
Port 1524 is commonly associated with the Ingreslock backdoor trojan related to the Ingres database software. Originally designed for internal database communication, over time, it has been widely abused by attackers to gain unauthorized access to systems, making it a known security concern. Both TCP and UDP protocols can be used on this port, increasing its attack surface and necessitating vigilant network monitoring and filtering..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 7,484
2 transports registered
payload readable on path
registered with iana
caution
rank 680 of 993 · top 68%
Technical Details
what runs on :1524Port 1524 was initially associated with Ingres, an enterprise relational database management system. Typically, Ingres used this port internally to enable remote management functions and database communication. It sometimes became exposed externally due to misconfigurations, creating risks for database environments relying on network interactions.
Historically, this port gained notoriety because malicious actors exploited it via the Ingreslock backdoor trojan. The trojan would listen on port 1524, enabling unauthorized remote shell access. Its presence was typically the result of post-compromise activity, where attackers installed it after initial exploitation to maintain persistence without raising suspicion.
Due to its connection with remote management and known abuses, security practitioners view any open port 1524 as suspicious unless explicitly required and controlled. Modern usage of this port for legitimate Ingres databases often avoids internet exposure, instead residing behind strong access controls and internal network segmentation.
Security Information
exposure of :1524risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
security averages 3.8 across 216 ports — this one sits 0.2 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common Vulnerabilities:
- Presence of the Ingreslock trojan, a known backdoor providing shell access
- Weak firewall configurations that leave port 1524 exposed externally
- Exploitation via lateral movement after initial compromise
- Lack of access controls on internal database services
Common Mitigations:
- Strictly block inbound and outbound traffic on port 1524 at perimeter and host-based firewalls unless explicitly required
- Use network intrusion detection systems (NIDS) to identify suspicious traffic or shell activity via this port
- Regularly scan hosts for unauthorized listeners on port 1524
- Harden authentication and disable unnecessary services in Ingres deployments
- Segment internal networks to minimize lateral movement risk
- Conduct regular malware and rootkit detection scans
Related Ports
the 8 most looked-up other ports in security — 216 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :443 | HTTPS | TCPtls | Web Services | caution | 65.9k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Squid Proxy HTTP | TCP | Web Services | caution | 45.8k |
| :8080 | HTTP Alternate | TCPtls | Web Services | caution | 44.9k |
| :7000 | Vuze HTTPS Tracker | TCPtls | Security | caution | 28.9k |
risk mix of the 8 listed
- caution100%
3 of 8 encrypted