There are no significant vulnerabilities in Bitcoin/Litecoin and their clones, so knowing the port would provide little advantage. The RPC port is, by default, only bound to 127.0.0.1, so any vulnerabilities that exist there wouldn't be directly externally accessible.
Stock Debian/Ubuntu (and other distros) are not terribly insecure out the box. In fact, more often than not, it is the incorrect configuration of software that opens holes on a machine. I would hazard that a box with a poorly configured FTP service is a much softer target than a stock Ubuntu box that is only really exposing SSH to the Internet.