Skip to main content

Port Details

Port
8888
Transport
TCP
Service
Jupyter
IANA service name
ddi-tcp-1, ddi-udp-1
Range
User port (1024-49151)

Security Exposure

The Jupyter Server documentation states that access to the server means access to running arbitrary code, and that connecting to kernels or terminals is equivalent to full permissions. Binding the server to all interfaces for remote use makes that code execution reachable from the network. Token authentication is on by default, and the documentation marks disabling it by setting empty token and password as not recommended unless access is handled at another layer.

Hardening

  • +Keep Jupyter bound to localhost and reach it through an SSH tunnel or an authenticated reverse proxy.
  • +Never disable token or password authentication on a server reachable from other hosts.
  • +Enable TLS when the server must listen on a network interface.
  • +Use JupyterHub for multi-user access instead of sharing a single-user server.

Monitoring

Alert on 8888 listeners bound to non-loopback addresses, and review server logs for logins and new kernel or terminal sessions from unexpected addresses.

Tools for Auditing and Monitoring Jupyter

osquery

Open Source
SIEM Tools

Operating system instrumentation framework that exposes low-level system telemetry as SQL tables for security monitoring.

LicenseApache-2.0 OR GPL-2.0-only
PlatformLinux, macOS, Windows

Falco

Open Source
Cloud Security Tools

Cloud-native runtime security engine that monitors Linux kernel system calls to detect anomalous behavior in containers.

LicenseApache-2.0
PlatformLinux

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

What runs on port 8888?→

Jupyter Server and Jupyter Notebook use 8888 by default. IANA's registration for the port is NewsEDGE (ddi-tcp-1 and ddi-udp-1).

Is it safe to expose Jupyter on port 8888?→

Only with authentication and TLS in place. Jupyter's documentation says server access means the ability to run arbitrary code.

How do I access a remote Jupyter server without opening 8888?→

Keep the server on localhost and forward the port through SSH, or put it behind an authenticated proxy. Jupyter's guidance points to JupyterHub for shared deployments.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8888 is not guaranteed to be Jupyter. Exploited-in-the-wild data from the CISA KEV catalog (CC0).