BuildNot yet confirmed elsewhere1 publisher3 min readPublished
Port 6379 draws 4.9 million answers in a scan that fingerprints only 142 Redis servers
ZoomEye queries run on 27 September counted 4.9 million services answering on Redis's default port 6379, against 142 fingerprinted as Redis. The larger figure counts reachable listeners, a list owners can check against Redis's rule that the server stay on trusted networks.
The Engineer · Build desk

What happened
- The port count misses Redis running on non-standard ports and instances bound only to a local interface, the deployment Redis intends.
- Redis's security documentation says the server should be reached only from the same host or a trusted network, behind a firewall otherwise.
- According to the post, Redis's default configuration needs no authentication on a local socket and makes authentication opt-in for network listeners.
- The post gives owners five checks covering bind address, password and protected mode, firewall scope, command restriction and persistence file location.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Exposure scoping for Redis in this dataset has to start from the port, because a fingerprint search would hand an owner about one candidate in 34,800 listeners.
- constraint Because the figure measures reachability from the scanner, it cannot be quoted as a count of unauthenticated Redis; that number needs a probe of each server.
- exposure Any listener in an owner's range that answers on 6379 without a password puts its stored data in reach of anyone and, where configuration permits, the host's files too.
The two counts differ by a factor of about 34,800 [15]. Put the other way, the product fingerprint matched roughly 0.003% of what answered on the port [16]. Both queries ran against ZoomEye's international dataset with the default all-asset scope [1]. The post's author called the fingerprint's coverage of Redis limited for exposure-scoping purposes [4]. Limited is a polite word for one match per 34,800 listeners [15].
The post argues that the port is the better identifier for Redis, on two grounds. Port 6379 is stable across versions and distributions, and the author wrote that it is not commonly reused by unrelated software in the index [17]. Redis's security guidance is also unambiguous, so the population of interest is defined by exposure, with no version or vulnerability to filter on [19]. The first ground sits uneasily beside the fingerprint result. If 6379 is rarely reused, the fingerprint is missing almost every Redis server on the port. If it is reused, software other than Redis inflates the 4.9 million [3][5].
The port count describes reachability from the scanning infrastructure [5]. For an answer on 6379 to be an exposed data store, the listener has to be Redis, it has to accept commands without a password, and the scanner's view has to match an attacker's. The port query speaks to the third condition and assumes the first. The author does not claim more. "A count of five million answers on the port does not mean five million exposed data stores. It means five million services where the question, is this an exposed data store, is worth asking of the owner," the author wrote [7].
Redis's documentation deserves credit for stating its deployment rule outright [8]. The access model it describes rests on protected mode, a password the operator can choose to set, and a plain statement that Redis is not meant to face the internet [9]. The risk sits with network listeners where nobody opted into a password [11]. "A service reachable from an untrusted network without authentication is a data store that answers to anyone," the author wrote [12].
Of the post's five checks for owned hosts [13], the last is the least obvious. It asks owners to make sure Redis saves its persistence files somewhere a client without credentials cannot steer [13]. The check is aimed at the file writes that Redis's recovery instructions describe for a reached instance, where configuration permits them [10].
For an organisation's own ranges, the author wrote, the port scope is the one that produces a reviewable candidate list [18]. The post also recommends that reports state the fingerprint count and the port count, and say which one the analysis relies on and why [14].
What to watch
- A rerun that sends a Redis handshake to the 6379 population and reports how many servers accept commands without a password.
- A revised ZoomEye Redis fingerprint, and whether a rerun narrows the gap of about 34,800 port answers per product match.
- A breakdown of which software other than Redis answers on 6379 in the index.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence40
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Two queries were run against ZoomEye's international dataset on 2026-09-27 with the default all asset scope.
- [2]
The query app="Redis" returned 142 matching services.
- [3]
The query port="6379" returned 4,937,184 matching services.
- [4]
The author said the product fingerprint result is small enough that the dataset's coverage for Redis can be described as limited for exposure-scoping purposes.
- [5]
The port count includes software other than Redis that listens on 6379, and it describes reachability from the scanning infrastructure.
- [6]
The port count excludes Redis instances on non-standard ports and instances bound to a local interface only, which is the intended deployment.
- [7]
"A count of five million answers on the port does not mean five million exposed data stores. It means five million services where the question, is this an exposed data store, is worth asking of the owner."
- [8]
Redis's security documentation says the server should be accessed only by clients on the same host or a trusted network, and protected with a firewall when it is not.
- [9]
The Redis security page describes an access control model built on protected mode, an optional password, and the rule that the server is not intended to be exposed to the internet.
- [10]
Redis's recovery instructions for a compromised instance say a reached instance allows the operator's data to be read and, where the configuration permits it, allows the server to write files.
- [11]
According to the post, Redis's default configuration requires no authentication on a local socket, and authentication is opt-in for network listeners.
- [12]
"A service reachable from an untrusted network without authentication is a data store that answers to anyone."
- [13]
For each owned service answering on 6379, the post lists five checks: bind address (local or network interface); whether a password is configured and protected mode enabled; whether the firewall rule is limited to the application hosts that need access; whether command rename or disable configuration is applied where the deployment permits; and that persistence files are not written to a location an unauthenticated client could influence.
- [14]
The post recommends that reports state the product fingerprint, state the port, and state which one the analysis relies on and why.
- [15]
Port-6379 answers outnumber Redis fingerprint matches by a factor of about 34,800.
- [16]
The Redis fingerprint matched roughly 0.003% of the services answering on port 6379.
- [17]
The author argued that Redis's default port is stable across versions and distributions and is not commonly reused by unrelated software in the index.
ReportedInsufficientSource: dev.to post2 sources— create a free account to open themView cited source - [18]
The author wrote that for Redis the port scope is the one that produces a reviewable candidate list for the organisation's own ranges.
ReportedInsufficientSource: dev.to post2 sources— create a free account to open themView cited source - [19]
The post says Redis's security guidance is unambiguous, so the population of interest is defined by the exposure, not by a version or a vulnerability.
ReportedInsufficientSource: dev.to post2 sources— create a free account to open themView cited source
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toRedis: 142 Product Matches Beside 4.9 Million Answers on Port 6379
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Internet Exposure ScanningFollow
- Database SecurityFollow