Port 6623Kerberos V5 Telnet
Kerberos-authenticated Telnet service; session traffic is not encrypted unless Telnet encryption is separately negotiated.
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 2/10
- lookups
- 0
2 transports registered
payload readable on path
registered with iana
safe
rank 993 of 5,745 · top 17%
also known as ktelnet, Kerberos Telnet
Technical Details
what runs on :6623Kerberos V5 Telnet is Telnet with Kerberos authentication, using Telnet's in-band option negotiation (RFC 854) and the Kerberos V5 authentication option (RFC 2942). Telnet sessions are stream-oriented and normally run over TCP; the registry also lists UDP for this service, but UDP is not the usual transport for an interactive Telnet session. Port 6623 is an assigned alternate service port; conventional Telnet commonly uses TCP/23. Kerberos authentication does not by itself encrypt the session data—Telnet encryption is a separate negotiated option.
Security Information
exposure of :6623risk score
2/ 10safe
routine exposure. this port is rarely the way in on its own — keep it patched and logged and move on.
remote access averages 3.8 across 219 ports — this one sits 1.8 below.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Kerberos can provide strong authentication, but session contents may still travel in cleartext unless Telnet encryption is negotiated. Telnet is a legacy remote-access protocol and should not normally be exposed to the internet; prefer SSH. The assignment is obscure and has not appeared open in the cited Nmap scan data, so an unexpected listener on 6623 should be verified rather than assumed to be Kerberos Telnet.
Related Ports
the 8 most looked-up other ports in remote access — 219 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8000 | Intel Remote Desktop / Alternate HTTP Port | TCP | Web Services | safe | 84.3k |
| :8888 | D2GS Admin Console | TCP | Remote Access | caution | 83.7k |
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :8008 | IBM HTTP Server Admin | TCP | Web Services | caution | 58.3k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :23 | Telnet | TCP | Remote Access | caution | 34.8k |
risk mix of the 8 listed
- safe13%
- caution88%
0 of 8 encrypted