:8009
(TCP)
Apache JServ Protocol (AJP)
Critical リスクTCP — Web
On this page
ポート概要
ポート番号
8009
サービス名
Apache JServ Protocol (AJP)
トランスポートプロトコル
TCP
カテゴリ
Web
セキュリティリスク
Critical
ポート範囲
登録済み (1024-49151)
ポートとは 8009?
Port 8009 is the default port for Apache JServ Protocol (AJP), used to proxy requests from an Apache HTTP server to Apache Tomcat or other Java application servers. The Ghostcat vulnerability (CVE-2020-1938) allowed unauthenticated file reads and RCE through AJP, resulting in widespread exploitation of exposed port 8009. This port should be disabled or restricted if not actively used for reverse proxying.
TCP
Web
よく使われる
セキュリティの考慮事項
ポート8009(Apache JServ Protocol (AJP))は重大なリスクに分類されています。このポートはパブリックインターネットに公開すべきではありません。このサービスは暗号化なしでデータを送信するため、盗聴、認証情報の窃取、中間者攻撃に対して脆弱です。
推奨事項: このポートをファイアウォールでブロックしてください。代わりに暗号化された代替手段(SSH、SFTP、HTTPS)を使用してください。