Skip to content

Open Ports Explainer: Paste ss -tulpn, See What Is Exposed

Quick Answer

The Open Ports Explainer reads the output of ss -tulpn, ss -ltnpe, netstat -tulpn or lsof -i -P -n and explains every listening socket in plain English. For each one it shows the reachability scope from the Local Address column: 127.0.0.1 and ::1 are loopback only, 0.0.0.0 is every IPv4 interface, [::] or * is every interface, and a specific address is that interface only. It names the owner from the Process column, or from the systemd cgroup when you ran ss -e without root, adds a note for the port (systemd-resolved on 127.0.0.53:53, LLMNR on 5355, mDNS on 5353, Postgres on 5432), and flags the known problems: a database or the Docker API on a wildcard address, a published container port, an empty Process column, and a full accept queue. Each row gets the next command to run. Nothing is sent anywhere, and addresses are redacted in share links by default.

How to use the Open Ports Explainer: Paste ss -tulpn, See What Is Exposed

  1. 1Run `ss -tulpn` (or `sudo ss -tulpn` to see every process) and paste the whole output, header included.
  2. 2Read the summary: listeners, how many are reachable from the network, and how many are flagged.
  3. 3Open each flagged card and run its next command to confirm what owns the socket.
  4. 4Copy the baseline CSV and schedule the ports-audit script so a new listener alerts you next time.

Frequently Asked Questions

faq — tool

What is the difference between 0.0.0.0 and 127.0.0.1 in ss output?

127.0.0.1 is loopback: only programs on the same machine can connect, and every other machine gets "Connection refused". 0.0.0.0 means every IPv4 address the host has, including LAN, VPN and Docker bridge addresses. [::] is the IPv6 equivalent, and * is one socket for both families. Whether a 0.0.0.0 listener is reachable from outside still depends on your firewall and NAT, which ss cannot see.

faq — tool

Why is the Process column empty in ss -tulpn?

ss can only read the owning process of sockets that belong to your own user unless it runs as root, so rows owned by system services come back with no users:(( )) field. Run sudo ss -tulpn to see every process. Without root, ss -ltnpe adds uid and the cgroup, which names the systemd unit that owns the socket, such as systemd-resolved.service or docker.service.

faq — tool

What is listening on port 5355 and 127.0.0.53:53 on Linux?

Both are systemd-resolved. 127.0.0.53:53 and 127.0.0.54:53 are its local DNS stub resolvers, reachable only from the machine itself. Port 5355 on 0.0.0.0 and [::] is its LLMNR responder, which answers name lookups from the local network. If you do not need LLMNR, set LLMNR=no in a drop-in under /etc/systemd/resolved.conf.d/ and restart systemd-resolved.

faq — tool

What do Recv-Q and Send-Q mean on a LISTEN row?

On a listening TCP socket, Send-Q is the backlog limit the program asked for and Recv-Q is how many finished connections are waiting for the program to accept them. Recv-Q near zero is normal. Recv-Q at or above Send-Q means the queue is full: the service is running but not accepting, usually because it is hung or overloaded, and new clients wait or time out.

faq — tool

Does this tool scan my ports or send my output anywhere?

No. It never connects to any address; it only reads the text you paste, and the parsing runs in your browser. A share link carries the normalised rows in the URL fragment after the # sign, which browsers do not send to the server, and addresses other than loopback, wildcard and multicast are redacted in it by default.

PAID RESOURCE — $9

The Production Bash Toolkit

An operational script system + a 30-function shared library + a 52-page field guide. The production layer the free snippets don't cover.

Get the Toolkit →
curl -O bashlib-starter.sh

Get the bashlib starter

Ten functions I source into every script on my own boxes — strict-mode setup, an ERR trap that names the failing line, lock and timeout wrappers, and cleanup that runs on every exit path. One email, no sequence.

Related Snippets