Skip to main content

Port Details

Port
9418
Transport
TCP
Service
Git protocol
IANA service name
git
Range
User port (1024-49151)

Security Exposure

The Pro Git book describes the Git protocol as offering no authentication or cryptography, and warns that cloning over git:// can lead to arbitrary code execution through tampering in transit. git daemon disables push (receive-pack) by default because anyone could push anything, including deleting refs, if it were enabled. With --export-all, every repository under the served path becomes readable.

Hardening

  • +Serve only repositories meant to be public, and avoid --export-all so each exported repository needs a git-daemon-export-ok file.
  • +Never enable receive-pack on git daemon outside a closed, trusted network.
  • +Use HTTPS or SSH for any repository that needs authentication or integrity in transit.
  • +Use --base-path and --strict-paths to limit which directories the daemon can serve.

Monitoring

Track which hosts run git daemon and which repositories they export, and alert on 9418 listeners on hosts that hold private code.

Tools for Auditing and Monitoring Git protocol

Gitleaks

Open Source
Application Security Tools

Lightweight open-source secret scanner for git repositories, CI/CD pipelines, and pre-commit hooks, detecting hardcoded API keys, tokens, and passwords.

LicenseMIT
PlatformLinux, macOS, Windows

TruffleHog

Free / Commercial
Application Security Tools

Open-source and commercial secret scanner with verified credential detection across source code, cloud storage, CI/CD, and SaaS platforms.

LicenseAGPL-3.0-only
PlatformLinux, macOS, Windows

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

What is port 9418 used for?→

It is the Git native protocol port, served by git daemon for git:// URLs.

Is the git:// protocol secure?→

No. It has no authentication or encryption, and the Git documentation advises avoiding cloning over git:// unless the risks are understood.

Can people push to git daemon on 9418?→

Push is disabled by default. Enabling receive-pack would let anyone push because the protocol has no authentication.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 9418 is not guaranteed to be Git protocol. Exploited-in-the-wild data from the CISA KEV catalog (CC0).