20
FTP Data
Critical RiskTCP — File Transfer
Port Overview
Port Number
20
Service Name
FTP Data
Transport Protocol
TCP
Category
File Transfer
Security Risk
Critical
Port Range
Well-Known (0-1023)
What is Port 20?
FTP data transfer channel. Used in active mode FTP for the server to establish a data connection back to the client. Credentials and files are sent in plaintext.
TCP
File Transfer
Commonly Used
Security Considerations
Port 20 (FTP Data) is classified as critical risk. This port should not be exposed to the public internet. The service transmits data without encryption, making it vulnerable to eavesdropping, credential theft, and man-in-the-middle attacks.
Recommendation: Block this port at the firewall. Use encrypted alternatives (SSH, SFTP, HTTPS) instead.