Apache JServ Protocol (AJP)
Critical RisikoTCP — Web
On this page
Ikhtisar Port
Apa itu Port 8009?
Port 8009 is the default port for Apache JServ Protocol (AJP), used to proxy requests from an Apache HTTP server to Apache Tomcat or other Java application servers. The Ghostcat vulnerability (CVE-2020-1938) allowed unauthenticated file reads and RCE through AJP, resulting in widespread exploitation of exposed port 8009. This port should be disabled or restricted if not actively used for reverse proxying.
Pertimbangan Keamanan
Port 8009 (Apache JServ Protocol (AJP)) diklasifikasikan sebagai risiko kritis. Port ini tidak boleh diekspos ke internet publik. Layanan ini mentransmisikan data tanpa enkripsi, sehingga rentan terhadap penyadapan, pencurian kredensial, dan serangan man-in-the-middle.
Rekomendasi: Blokir port ini di firewall. Gunakan alternatif terenkripsi (SSH, SFTP, HTTPS) sebagai gantinya.