TCP 21
Synopsis
- TCP port 21 is the control channel for the File Transfer Protocol (FTP) and for FTPS in explicit TLS mode.
- Common FTP servers that bind to 21 include vsftpd, ProFTPD, and Pure-FTPd on Linux/Unix systems.
- On Windows, Microsoft IIS FTP Server and FileZilla Server listen on port 21 by default.
- Enterprise servers such as Progress WS_FTP Server and Serv-U FTP Server use port 21 for FTP/explicit FTPS.
- Many NAS and appliance platforms expose FTP on 21, including Synology DSM, QNAP QTS, and home routers with USB storage (e.g., ASUSWRT, TP-Link).
- Hosting panels often run FTP on 21, such as cPanel/WHM deployments with Pure-FTPd or ProFTPD, and AWS Transfer Family for FTP/FTPS uses 21 for the control connection.
- Port 21 services are frequently targeted for hacking due to cleartext credentials and misconfigurations (anonymous access, weak passwords), with notable issues like the vsftpd 2.3.4 backdoor, ProFTPD vulnerabilities, and FTP bounce attacks.
Observed activity
Last 30 days
Detailed chart