Port 42WINS

WINS (Windows Internet Name Service) is a Microsoft NetBIOS Name Server legacy service used primarily for name resolution on Windows networks. It enables clients to register and resolve NetBIOS names to IP addresses, facilitating easier communication in older Windows domain environments..

transport
tcp · udp

2 transports registered

in transit
cleartext

payload readable on path

assignment
unofficial

used by convention

risk
4/10

caution

lookups
16,416

rank 180 of 993 · top 18%

1 other service is registered on port 42. compare all 2

Technical Details

what runs on :42

Windows Internet Name Service (WINS) is a Microsoft-developed protocol designed for NetBIOS name resolution across IP networks. WINS maps NetBIOS names to dynamic IP addresses, allowing seamless connectivity between devices that rely on NetBIOS. It supports registering client names dynamically, querying name-to-IP mappings, and managing replication between WINS servers to maintain accuracy.

WINS operates over both TCP and UDP on port 42. UDP is commonly used for query and response messages due to its lower overhead, while TCP is leveraged for replication traffic and certain control messages to ensure reliability. The service maintains a database that dynamically updates as clients join or leave the network, helping reduce conflicts and stale records.

With the advent of modern DNS and Active Directory-integrated DNS, the reliance on WINS has diminished sharply. However, in legacy or mixed environments with older Windows systems, WINS might still exist to maintain compatibility with NetBIOS-dependent communications and applications.

Security Information

exposure of :42

risk score

4/ 10caution

worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.

network services averages 3.9 across 604 ports — this one sits 0.1 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

unofficial

used by convention, not registered — what answers here varies by deployment

reachable over

tcp · udp

udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite

security overview

Common Vulnerabilities:

  • WINS servers can be susceptible to denial-of-service (DoS) attacks via malformed name registration requests or flood of bogus queries.
  • Weak authentication mechanisms leave WINS open to unauthorized registrations or malicious updates, enabling spoofing attacks.
  • Lack of encryption means data exchanged can be intercepted or tampered with in transit.
  • Because WINS replicates with other servers, a compromised WINS server can affect others by distributing incorrect information.

Common Mitigations:

  • Segment legacy WINS traffic to isolated network zones with strict access controls.
  • Filter or block inbound and outbound port 42 traffic from untrusted networks.
  • Restrict which hosts are permitted to register or replicate names.
  • Disable or decommission WINS entirely where possible, migrating fully to DNS.
  • Regularly patch Windows servers to address protocol and service vulnerabilities.

the 8 most looked-up other ports in network services — 604 ports carry that label.

risk mix of the 8 listed

  • caution100%

0 of 8 encrypted