Port 8080: HTTP alternate port
Port 8080 is registered by IANA as http-alt, an alternate to port 80. Apache Tomcat configures its default non-TLS HTTP/1.1 connector on 8080. Shadowserver lists 8080 among the typical ports for open HTTP proxies.
Port Details
Security Exposure
Tomcat's default connector on 8080 is non-TLS, so credentials and session cookies sent to it are not encrypted. Shadowserver notes that open HTTP proxies, typically found on ports such as 3128, 1080 and 8080, are used for attacks and other forms of abuse. The Tomcat security guide also warns that its default web applications have had vulnerabilities in the past.
Hardening
- +Identify every service on 8080 and close the port where it is not needed.
- +Put application servers behind a TLS reverse proxy instead of exposing 8080 directly.
- +Require authentication on any proxy service and never run an open proxy.
- +Remove unused Tomcat connectors and default web applications such as examples, as the Tomcat security guide recommends.
Monitoring
Inventory listeners on TCP 8080, review access logs for administrative paths, and alert on proxy-style CONNECT requests from the internet.
Tools for Auditing and Monitoring HTTP Alternate
Nikto
Free / CommercialWeb server scanner that inspects web hosts for dangerous files, outdated server software, and misconfigured HTTP headers.
ZAP
Open SourceOpen-source web application security scanner and intercepting proxy for detecting web flaws during development and testing.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Static source analysis, dynamic scanners, and dependency vulnerability checkers.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
What is port 8080 used for?→
IANA registers 8080 as an HTTP alternate port, and Apache Tomcat uses it for its default HTTP connector.
Is port 8080 less secure than port 80?→
The port number itself does not change security. Whatever runs on 8080 needs the same TLS and access controls as any web service, and Tomcat's default 8080 connector does not use TLS.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8080 is not guaranteed to be HTTP Alternate. Exploited-in-the-wild data from the CISA KEV catalog (CC0).