Port 8008: HTTP alternate port
Port 8008 is registered by IANA as http-alt, an alternate HTTP port. The Matrix homeserver Synapse exposes its HTTP listener on localhost:8008 by default and expects a reverse proxy in front for HTTPS.
Port Details
Security Exposure
Synapse's default listener on 8008 is plain HTTP, so traffic to it is unencrypted. Synapse documentation calls the default 8008 listener suitable for local testing and says that for any practical use its APIs need to be served over HTTPS, with a reverse proxy as the recommended approach.
Hardening
- +Bind application listeners on 8008 to localhost and publish them through a TLS reverse proxy.
- +Block inbound 8008 at the perimeter unless a documented service needs it.
- +For Synapse, set bind_addresses to 127.0.0.1 when the reverse proxy runs on the same host, except in containerized deployments where the documentation says not to.
- +Identify what is listening on 8008 and remove unused services.
Monitoring
Inventory listeners on TCP 8008 and alert on plain HTTP traffic to that port from outside the expected network.
Tools for Auditing and Monitoring HTTP Alternate
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
httpx
Open SourceFast HTTP toolkit that probes services, captures response metadata, and fingerprints technologies to verify external attack surfaces.
Nuclei
Free / CommercialFast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.
Related Tool Categories
Frequently Asked Questions
What uses port 8008?→
IANA registers 8008 as http-alt. The Synapse Matrix homeserver uses 8008 as its default HTTP listener.
Should port 8008 be reachable from the internet?→
Usually not directly. Synapse recommends serving its APIs over HTTPS through a reverse proxy instead of exposing 8008.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8008 is not guaranteed to be HTTP Alternate. Exploited-in-the-wild data from the CISA KEV catalog (CC0).