Apache JServ Protocol (AJP)
Critical RisqueTCP — Web
On this page
Aperçu du port
Qu'est-ce que le port 8009?
Port 8009 is the default port for Apache JServ Protocol (AJP), used to proxy requests from an Apache HTTP server to Apache Tomcat or other Java application servers. The Ghostcat vulnerability (CVE-2020-1938) allowed unauthenticated file reads and RCE through AJP, resulting in widespread exploitation of exposed port 8009. This port should be disabled or restricted if not actively used for reverse proxying.
Considérations de sécurité
Le port 8009 (Apache JServ Protocol (AJP)) est classifié comme risque critique. Ce port ne doit pas être exposé sur l'internet public. Le service transmet des données sans chiffrement, le rendant vulnérable aux écoutes clandestines, au vol d'identifiants et aux attaques de type homme du milieu.
Recommandation : Bloquez ce port au niveau du pare-feu. Utilisez des alternatives chiffrées (SSH, SFTP, HTTPS) à la place.