Skip to main content

Port Details

Port
8080
Transport
TCP
Service
HTTP Alternate
IANA service name
http-alt
Range
User port (1024-49151)
Related ports

Security Exposure

Tomcat's default connector on 8080 is non-TLS, so credentials and session cookies sent to it are not encrypted. Shadowserver notes that open HTTP proxies, typically found on ports such as 3128, 1080 and 8080, are used for attacks and other forms of abuse. The Tomcat security guide also warns that its default web applications have had vulnerabilities in the past.

Hardening

  • +Identify every service on 8080 and close the port where it is not needed.
  • +Put application servers behind a TLS reverse proxy instead of exposing 8080 directly.
  • +Require authentication on any proxy service and never run an open proxy.
  • +Remove unused Tomcat connectors and default web applications such as examples, as the Tomcat security guide recommends.

Monitoring

Inventory listeners on TCP 8080, review access logs for administrative paths, and alert on proxy-style CONNECT requests from the internet.

Tools for Auditing and Monitoring HTTP Alternate

Nikto

Free / Commercial
Vulnerability Scanning

Web server scanner that inspects web hosts for dangerous files, outdated server software, and misconfigured HTTP headers.

LicenseGPL-3.0-only (code); database files restricted to use with Nikto
PlatformLinux, macOS, Windows

ZAP

Open Source
Application Security Tools

Open-source web application security scanner and intercepting proxy for detecting web flaws during development and testing.

LicenseApache-2.0
PlatformLinux, Windows, macOS

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

What is port 8080 used for?→

IANA registers 8080 as an HTTP alternate port, and Apache Tomcat uses it for its default HTTP connector.

Is port 8080 less secure than port 80?→

The port number itself does not change security. Whatever runs on 8080 needs the same TLS and access controls as any web service, and Tomcat's default 8080 connector does not use TLS.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8080 is not guaranteed to be HTTP Alternate. Exploited-in-the-wild data from the CISA KEV catalog (CC0).