Port 9000: Shared default port for PHP-FPM FastCGI, SonarQube, MinIO, and Portainer
IANA registers 9000 as cslistener, but several unrelated products use it as a default. The stock PHP-FPM pool configuration listens on 127.0.0.1:9000 for FastCGI, SonarQube Server opens on http://localhost:9000, MinIO serves its S3 API on 9000, and Portainer can expose a legacy HTTP interface on 9000.
Port Details
Security Exposure
The risk depends on which product answers. SonarQube Server ships with default administrator credentials of admin/admin, and MinIO's deployment examples show minioadmin as the default root user and password, so an exposed instance with unchanged defaults is open to anyone who reaches it. The stock PHP-FPM pool binds FastCGI to 127.0.0.1:9000, and its listen.allowed_clients option accepts connections from any address when left blank.
Hardening
- +Identify which product listens on 9000 on each host before writing firewall rules.
- +Change default administrator credentials for SonarQube and MinIO before the service is reachable from any network.
- +Keep PHP-FPM on 127.0.0.1 or a Unix socket and never expose its FastCGI port.
- +Prefer the HTTPS listener (Portainer 9443) over legacy plain HTTP on 9000.
Monitoring
Scan for unexpected 9000 listeners and fingerprint the service behind each one. Alert on logins to SonarQube, MinIO, or Portainer with default accounts.
PHP-FPM / SonarQube / MinIO Vulnerabilities
3 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2023-28434 | MinIO is vulnerable to privilege escalation on Linux/MacOS | minio | 8.8 | 7.9% | KEV | 2023-03-22 |
| CVE-2023-28432 | Minio Information Disclosure in Cluster Deployment | minio | 7.5 | 84.0% | KEV | 2023-03-22 |
| CVE-2019-11043 | Underflow in PHP-FPM can lead to RCE | PHP | 8.7 | 99.8% | KEV | 2019-10-28 |
Tools for Auditing and Monitoring PHP-FPM / SonarQube / MinIO
Trivy
Open SourceComprehensive security scanner for container images, file systems, Git repositories, and Kubernetes configurations to detect CVEs.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nuclei
Free / CommercialFast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.
Related Tool Categories
Static source analysis, dynamic scanners, and dependency vulnerability checkers.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
What is running on port 9000?→
Common defaults include PHP-FPM (FastCGI), SonarQube Server, the MinIO S3 API, and Portainer's legacy HTTP interface. IANA's registration is cslistener.
Should PHP-FPM port 9000 be open?→
No. The default PHP-FPM pool configuration listens only on 127.0.0.1:9000, and the FastCGI port should stay reachable only by the local web server.
What is the default login for services on port 9000?→
SonarQube Server documents admin/admin, and MinIO examples show minioadmin for both user and password. Both should be changed immediately.
Which vulnerabilities affect the service on port 9000?→
This database lists 3 CVEs related to PHP-FPM / SonarQube / MinIO, 3 of them confirmed as exploited by CISA. Examples: CVE-2023-28434, CVE-2023-28432, CVE-2019-11043.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 9000 is not guaranteed to be PHP-FPM / SonarQube / MinIO. Exploited-in-the-wild data from the CISA KEV catalog (CC0).