Port 42WINS
WINS (Windows Internet Name Service) is a Microsoft NetBIOS Name Server legacy service used primarily for name resolution on Windows networks. It enables clients to register and resolve NetBIOS names to IP addresses, facilitating easier communication in older Windows domain environments..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 16,416
2 transports registered
payload readable on path
used by convention
caution
rank 180 of 993 · top 18%
1 other service is registered on port 42. compare all 2 →
Technical Details
what runs on :42Windows Internet Name Service (WINS) is a Microsoft-developed protocol designed for NetBIOS name resolution across IP networks. WINS maps NetBIOS names to dynamic IP addresses, allowing seamless connectivity between devices that rely on NetBIOS. It supports registering client names dynamically, querying name-to-IP mappings, and managing replication between WINS servers to maintain accuracy.
WINS operates over both TCP and UDP on port 42. UDP is commonly used for query and response messages due to its lower overhead, while TCP is leveraged for replication traffic and certain control messages to ensure reliability. The service maintains a database that dynamically updates as clients join or leave the network, helping reduce conflicts and stale records.
With the advent of modern DNS and Active Directory-integrated DNS, the reliance on WINS has diminished sharply. However, in legacy or mixed environments with older Windows systems, WINS might still exist to maintain compatibility with NetBIOS-dependent communications and applications.
Security Information
exposure of :42risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common Vulnerabilities:
- WINS servers can be susceptible to denial-of-service (DoS) attacks via malformed name registration requests or flood of bogus queries.
- Weak authentication mechanisms leave WINS open to unauthorized registrations or malicious updates, enabling spoofing attacks.
- Lack of encryption means data exchanged can be intercepted or tampered with in transit.
- Because WINS replicates with other servers, a compromised WINS server can affect others by distributing incorrect information.
Common Mitigations:
- Segment legacy WINS traffic to isolated network zones with strict access controls.
- Filter or block inbound and outbound port 42 traffic from untrusted networks.
- Restrict which hosts are permitted to register or replicate names.
- Disable or decommission WINS entirely where possible, migrating fully to DNS.
- Regularly patch Windows servers to address protocol and service vulnerabilities.
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted