Port 8000: Alternate HTTP port for development servers
Port 8000 is a common alternate HTTP port, used by default by the Django development server and in the Python http.server examples. IANA assigns 8000 to irdmi, which differs from this common use.
Port Details
Security Exposure
Django states its runserver has not gone through security audits and must not be used in production, and Python warns that http.server only implements basic security checks. By default, python -m http.server binds to all interfaces and serves the current directory, so files in that directory become reachable from the network.
Hardening
- +Bind development servers to 127.0.0.1. This is the Django runserver default, and http.server accepts --bind 127.0.0.1.
- +Do not run Django runserver or Python http.server in production; use a production web server instead.
- +Block inbound 8000 at the host firewall on servers that do not need it.
Monitoring
Inventory listeners on TCP 8000 and alert on new ones on production hosts. Review web server logs for requests from outside the development network.
Tools for Auditing and Monitoring HTTP (development)
Nikto
Free / CommercialWeb server scanner that inspects web hosts for dangerous files, outdated server software, and misconfigured HTTP headers.
ZAP
Open SourceOpen-source web application security scanner and intercepting proxy for detecting web flaws during development and testing.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Static source analysis, dynamic scanners, and dependency vulnerability checkers.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
What runs on port 8000?→
Django's development server runs on port 8000 by default, and Python's http.server documentation uses 8000 in its examples. IANA's registered service for 8000 is irdmi.
Is it safe to expose port 8000?→
Not for development servers. Django says runserver is unsuitable for production, and Python says http.server is not recommended for production.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8000 is not guaranteed to be HTTP (development). Exploited-in-the-wild data from the CISA KEV catalog (CC0).