Port 8888: Jupyter Server / Jupyter Notebook web interface
IANA assigns 8888 to the NewsEDGE service (ddi-tcp-1 on TCP, ddi-udp-1 on UDP), but its common modern use is different. Jupyter Server runs at 127.0.0.1:8888 by default and serves the browser interface for notebooks, terminals, and kernels.
Port Details
Security Exposure
The Jupyter Server documentation states that access to the server means access to running arbitrary code, and that connecting to kernels or terminals is equivalent to full permissions. Binding the server to all interfaces for remote use makes that code execution reachable from the network. Token authentication is on by default, and the documentation marks disabling it by setting empty token and password as not recommended unless access is handled at another layer.
Hardening
- +Keep Jupyter bound to localhost and reach it through an SSH tunnel or an authenticated reverse proxy.
- +Never disable token or password authentication on a server reachable from other hosts.
- +Enable TLS when the server must listen on a network interface.
- +Use JupyterHub for multi-user access instead of sharing a single-user server.
Monitoring
Alert on 8888 listeners bound to non-loopback addresses, and review server logs for logins and new kernel or terminal sessions from unexpected addresses.
Tools for Auditing and Monitoring Jupyter
osquery
Open SourceOperating system instrumentation framework that exposes low-level system telemetry as SQL tables for security monitoring.
Falco
Open SourceCloud-native runtime security engine that monitors Linux kernel system calls to detect anomalous behavior in containers.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Static source analysis, dynamic scanners, and dependency vulnerability checkers.
CSPM scanners, container and Kubernetes policy engines, and cloud configuration auditing tools.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Frequently Asked Questions
What runs on port 8888?→
Jupyter Server and Jupyter Notebook use 8888 by default. IANA's registration for the port is NewsEDGE (ddi-tcp-1 and ddi-udp-1).
Is it safe to expose Jupyter on port 8888?→
Only with authentication and TLS in place. Jupyter's documentation says server access means the ability to run arbitrary code.
How do I access a remote Jupyter server without opening 8888?→
Keep the server on localhost and forward the port through SSH, or put it behind an authenticated proxy. Jupyter's guidance points to JupyterHub for shared deployments.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 8888 is not guaranteed to be Jupyter. Exploited-in-the-wild data from the CISA KEV catalog (CC0).