The Network Vulnerability Vector
When you provision a new Ubuntu server and install complex software stacks (like Docker, Apache, or MySQL), these applications immediately open specific network ports to listen for incoming connections. If a port is accidentally left open and exposed to the public internet without a firewall, automated scanning bots will discover it within minutes and attempt to exploit vulnerabilities in the listening service. To secure your infrastructure, you must execute a comprehensive audit of every single open port on the machine.
How to Find Open Ports
The modern Linux networking stack provides a highly efficient command-line utility designed specifically to dump the state of all listening sockets directly to your terminal.
1. Open your terminal application or connect to your server via SSH.
2. You will utilize the ss (socket statistics) command, which has largely replaced the legacy netstat utility. To ensure you see all system-level processes, you must execute the command with superuser privileges.
3. Type the following command exactly:
sudo ss -tulpn
4. Command Breakdown:
* -t: Show TCP ports.
* -u: Show UDP ports.
* -l: Show only listening sockets (ports waiting for connections).
* -p: Show the exact process name (e.g., `nginx` or `sshd`) that is holding the port open.
* -n: Do not resolve service names; show the raw numerical port (e.g., `80` instead of `http`).
5. Press Enter. The terminal will output a tightly formatted table. Look specifically at the Local Address:Port column (e.g., `0.0.0.0:22` means port 22 is open on all interfaces). Review the final column to identify the exact application responsible for the exposure.