Skip to main content

Port Details

Port
9000
Transport
TCP
Service
PHP-FPM / SonarQube / MinIO
IANA service name
cslistener
Range
User port (1024-49151)
Related ports
90019443

Security Exposure

The risk depends on which product answers. SonarQube Server ships with default administrator credentials of admin/admin, and MinIO's deployment examples show minioadmin as the default root user and password, so an exposed instance with unchanged defaults is open to anyone who reaches it. The stock PHP-FPM pool binds FastCGI to 127.0.0.1:9000, and its listen.allowed_clients option accepts connections from any address when left blank.

Hardening

  • +Identify which product listens on 9000 on each host before writing firewall rules.
  • +Change default administrator credentials for SonarQube and MinIO before the service is reachable from any network.
  • +Keep PHP-FPM on 127.0.0.1 or a Unix socket and never expose its FastCGI port.
  • +Prefer the HTTPS listener (Portainer 9443) over legacy plain HTTP on 9000.

Monitoring

Scan for unexpected 9000 listeners and fingerprint the service behind each one. Alert on logins to SonarQube, MinIO, or Portainer with default accounts.

PHP-FPM / SonarQube / MinIO Vulnerabilities

3 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2023-28434
MinIO is vulnerable to privilege escalation on Linux/MacOS
minio8.87.9%KEV2023-03-22
CVE-2023-28432
Minio Information Disclosure in Cluster Deployment
minio7.584.0%KEV2023-03-22
CVE-2019-11043
Underflow in PHP-FPM can lead to RCE
PHP8.799.8%KEV2019-10-28

Tools for Auditing and Monitoring PHP-FPM / SonarQube / MinIO

Trivy

Open Source
Cloud Security Tools

Comprehensive security scanner for container images, file systems, Git repositories, and Kubernetes configurations to detect CVEs.

LicenseApache-2.0
PlatformLinux, macOS, Windows

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nuclei

Free / Commercial
Vulnerability Scanning

Fast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.

LicenseMIT
PlatformLinux, macOS, Windows

Frequently Asked Questions

What is running on port 9000?→

Common defaults include PHP-FPM (FastCGI), SonarQube Server, the MinIO S3 API, and Portainer's legacy HTTP interface. IANA's registration is cslistener.

Should PHP-FPM port 9000 be open?→

No. The default PHP-FPM pool configuration listens only on 127.0.0.1:9000, and the FastCGI port should stay reachable only by the local web server.

What is the default login for services on port 9000?→

SonarQube Server documents admin/admin, and MinIO examples show minioadmin for both user and password. Both should be changed immediately.

Which vulnerabilities affect the service on port 9000?→

This database lists 3 CVEs related to PHP-FPM / SonarQube / MinIO, 3 of them confirmed as exploited by CISA. Examples: CVE-2023-28434, CVE-2023-28432, CVE-2019-11043.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 9000 is not guaranteed to be PHP-FPM / SonarQube / MinIO. Exploited-in-the-wild data from the CISA KEV catalog (CC0).