Skip to main content

Port Details

Port
8000
Transport
TCP
Service
HTTP (development)
IANA service name
irdmi
Range
User port (1024-49151)
Related ports

Security Exposure

Django states its runserver has not gone through security audits and must not be used in production, and Python warns that http.server only implements basic security checks. By default, python -m http.server binds to all interfaces and serves the current directory, so files in that directory become reachable from the network.

Hardening

  • +Bind development servers to 127.0.0.1. This is the Django runserver default, and http.server accepts --bind 127.0.0.1.
  • +Do not run Django runserver or Python http.server in production; use a production web server instead.
  • +Block inbound 8000 at the host firewall on servers that do not need it.

Monitoring

Inventory listeners on TCP 8000 and alert on new ones on production hosts. Review web server logs for requests from outside the development network.

Tools for Auditing and Monitoring HTTP (development)

Nikto

Free / Commercial
Vulnerability Scanning

Web server scanner that inspects web hosts for dangerous files, outdated server software, and misconfigured HTTP headers.

LicenseGPL-3.0-only (code); database files restricted to use with Nikto
PlatformLinux, macOS, Windows

ZAP

Open Source
Application Security Tools

Open-source web application security scanner and intercepting proxy for detecting web flaws during development and testing.

LicenseApache-2.0
PlatformLinux, Windows, macOS

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

What runs on port 8000?→

Django's development server runs on port 8000 by default, and Python's http.server documentation uses 8000 in its examples. IANA's registered service for 8000 is irdmi.

Is it safe to expose port 8000?→

Not for development servers. Django says runserver is unsuitable for production, and Python says http.server is not recommended for production.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8000 is not guaranteed to be HTTP (development). Exploited-in-the-wild data from the CISA KEV catalog (CC0).