Skip to main content

Port Details

Port
8088
Transport
TCP
Service
YARN / Splunk HEC
IANA service name
radan-http
Range
User port (1024-49151)
Related ports
8032

Security Exposure

Hadoop's default hadoop.security.authentication value is "simple", which the Secure Mode guide defines as no authentication, and the guide expects operators to restrict all network access to a cluster that has not been secured. Alibaba Cloud reported a Kinsing botnet variant that spread through unauthorized access to the Hadoop YARN REST API and the YARN RPC service, then downloaded and started cryptocurrency mining software. On Splunk, HEC accepts events from any client that presents a valid token, so a leaked token is enough to write events into the index.

Hardening

  • +Block 8088 at the perimeter and allow it only from the networks that administer the cluster or submit jobs.
  • +Configure Kerberos authentication for Hadoop as described in the Hadoop Secure Mode guide instead of running in the default simple mode.
  • +Turn on HTTPS for the YARN web interfaces with the yarn.http.policy setting.
  • +Enable SSL on the Splunk HEC listener and disable HEC tokens that are no longer in use.

Monitoring

Review ResourceManager application submissions for unknown users or unexpected application names, and alert on inbound 8088 connections from outside the cluster's management networks. For HEC, watch for events arriving under tokens or source addresses that do not match known senders.

Tools for Auditing and Monitoring YARN / Splunk HEC

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nuclei

Free / Commercial
Vulnerability Scanning

Fast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.

LicenseMIT
PlatformLinux, macOS, Windows

Zeek

Open Source
Network Monitoring Tools

Network security monitoring framework that translates raw packet traffic into structured transaction logs and network events.

LicenseBSD-3-Clause
PlatformLinux, FreeBSD, macOS, OpenBSD

Frequently Asked Questions

What runs on port 8088?→

The IANA registry lists radan-http for 8088. In practice, Hadoop YARN uses it for the ResourceManager web application, and Splunk uses it as the default HTTP Event Collector port.

Is port 8088 TCP or UDP?→

IANA lists both TCP and UDP for radan-http. YARN and Splunk HEC both run over HTTP or HTTPS, which uses TCP.

Should port 8088 be open to the internet?→

Not for a Hadoop cluster in its default configuration. The Hadoop documentation says a cluster without Kerberos security depends on restricting network access to keep attackers out.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8088 is not guaranteed to be YARN / Splunk HEC. Exploited-in-the-wild data from the CISA KEV catalog (CC0).