How to Check Open Ports in Ubuntu

The Socket Interrogation Vector

When engineering a headless Ubuntu server, every active background daemon (Apache, PostgreSQL, SSH, Docker) mathematically binds itself to a specific numerical port (ranging from 1 to 65535) to listen for inbound data payloads. If a rogue malware process breaches the server, it will quietly spin up a hidden daemon bound to a high-range port to establish a command-and-control connection. Conversely, if your web server refuses to load, you must mathematically verify that Apache is actually listening on Port `80`. You must instruct the Linux kernel to execute a comprehensive dump of all active, listening sockets, mapping every open port to its specific Process ID (PID).

How to Check Open Ports in Ubuntu

The legacy `netstat` command has been mathematically deprecated in modern Ubuntu architectures. The supreme execution pathway is now the `ss` (Socket Statistics) utility, which interfaces more efficiently with the kernel.

1. Open your terminal application or connect to the server via SSH.
2. Phase 1: The Master Socket Dump (The `ss` Command):
* To force the kernel to render a highly specific grid of all actively listening TCP and UDP ports.
* Type exactly (you must utilize `sudo` to extract the exact PID of the daemons):
sudo ss -tulpn
* Press Enter and authenticate.
* The Cryptographic Translation of the Flags:
* `-t`: Display TCP sockets.
* `-u`: Display UDP sockets.
* `-l`: Only display listening sockets (ignore active outbound connections).
* `-p`: Render the specific Process ID (PID) and daemon name utilizing the port.
* `-n`: Do not resolve service names (display raw IP and Port numbers, e.g., `80` instead of `http`), ensuring absolute mathematical accuracy.
* The Diagnostic Dump: The terminal outputs a complex matrix. Look at the `Local Address:Port` column. If you see `0.0.0.0:22`, it means the SSH daemon is actively listening on Port 22 across all IPv4 interfaces.
3. Phase 2: The Lsof Override (List Open Files):
* In UNIX, everything is mathematically treated as a file, including network sockets. The `lsof` command is a powerful alternative for deep interrogation.
* Type exactly:
sudo lsof -i -P -n | grep LISTEN
* Press Enter.
* This outputs a highly sterile, readable list displaying the Command (e.g., `apache2`), the User (`root`), and the specific Port (`*:80 (LISTEN)`).
4. Phase 3: The Surgical PID Annihilation (Kill Command):
* If the interrogation reveals a rogue daemon running on Port `8888`, and `ss` identifies its PID as `4052`.
* Execute a God-level kill signal: sudo kill -9 4052. The socket is instantly destroyed.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.