Apache JServ Protocol (AJP)
Critical RisikoTCP — Web
On this page
Port-Übersicht
Was ist Port 8009?
Port 8009 is the default port for Apache JServ Protocol (AJP), used to proxy requests from an Apache HTTP server to Apache Tomcat or other Java application servers. The Ghostcat vulnerability (CVE-2020-1938) allowed unauthenticated file reads and RCE through AJP, resulting in widespread exploitation of exposed port 8009. This port should be disabled or restricted if not actively used for reverse proxying.
Sicherheitshinweise
Port 8009 (Apache JServ Protocol (AJP)) ist als kritisches Risiko eingestuft. Dieser Port sollte nicht im öffentlichen Internet exponiert werden. Der Dienst überträgt Daten ohne Verschlüsselung und ist dadurch anfällig für Abhörangriffe, Zugangsdatendiebstahl und Man-in-the-Middle-Angriffe.
Empfehlung: Sperren Sie diesen Port an der Firewall. Verwenden Sie stattdessen verschlüsselte Alternativen (SSH, SFTP, HTTPS).