Skip to content

BuildNot yet confirmed elsewhere1 publisher3 min readPublished

Port 6379 draws 4.9 million answers in a scan that fingerprints only 142 Redis servers

ZoomEye queries run on 27 September counted 4.9 million services answering on Redis's default port 6379, against 142 fingerprinted as Redis. The larger figure counts reachable listeners, a list owners can check against Redis's rule that the server stay on trusted networks.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying Port 6379 draws 4.9 million answers in a scan that fingerprints only 142 Redis servers
Generated illustration

What happened

  • The port count misses Redis running on non-standard ports and instances bound only to a local interface, the deployment Redis intends.
  • Redis's security documentation says the server should be reached only from the same host or a trusted network, behind a firewall otherwise.
  • According to the post, Redis's default configuration needs no authentication on a local socket and makes authentication opt-in for network listeners.
  • The post gives owners five checks covering bind address, password and protected mode, firewall scope, command restriction and persistence file location.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision Exposure scoping for Redis in this dataset has to start from the port, because a fingerprint search would hand an owner about one candidate in 34,800 listeners.
  • constraint Because the figure measures reachability from the scanner, it cannot be quoted as a count of unauthenticated Redis; that number needs a probe of each server.
  • exposure Any listener in an owner's range that answers on 6379 without a password puts its stored data in reach of anyone and, where configuration permits, the host's files too.

The two counts differ by a factor of about 34,800 [15]. Put the other way, the product fingerprint matched roughly 0.003% of what answered on the port [16]. Both queries ran against ZoomEye's international dataset with the default all-asset scope [1]. The post's author called the fingerprint's coverage of Redis limited for exposure-scoping purposes [4]. Limited is a polite word for one match per 34,800 listeners [15].

The post argues that the port is the better identifier for Redis, on two grounds. Port 6379 is stable across versions and distributions, and the author wrote that it is not commonly reused by unrelated software in the index [17]. Redis's security guidance is also unambiguous, so the population of interest is defined by exposure, with no version or vulnerability to filter on [19]. The first ground sits uneasily beside the fingerprint result. If 6379 is rarely reused, the fingerprint is missing almost every Redis server on the port. If it is reused, software other than Redis inflates the 4.9 million [3][5].

The port count describes reachability from the scanning infrastructure [5]. For an answer on 6379 to be an exposed data store, the listener has to be Redis, it has to accept commands without a password, and the scanner's view has to match an attacker's. The port query speaks to the third condition and assumes the first. The author does not claim more. "A count of five million answers on the port does not mean five million exposed data stores. It means five million services where the question, is this an exposed data store, is worth asking of the owner," the author wrote [7].

Redis's documentation deserves credit for stating its deployment rule outright [8]. The access model it describes rests on protected mode, a password the operator can choose to set, and a plain statement that Redis is not meant to face the internet [9]. The risk sits with network listeners where nobody opted into a password [11]. "A service reachable from an untrusted network without authentication is a data store that answers to anyone," the author wrote [12].

Of the post's five checks for owned hosts [13], the last is the least obvious. It asks owners to make sure Redis saves its persistence files somewhere a client without credentials cannot steer [13]. The check is aimed at the file writes that Redis's recovery instructions describe for a reached instance, where configuration permits them [10].

For an organisation's own ranges, the author wrote, the port scope is the one that produces a reviewable candidate list [18]. The post also recommends that reports state the fingerprint count and the port count, and say which one the analysis relies on and why [14].

What to watch

  • A rerun that sends a Redis handshake to the 6379 population and reports how many servers accept commands without a password.
  • A revised ZoomEye Redis fingerprint, and whether a rerun narrows the gap of about 34,800 port answers per product match.
  • A breakdown of which software other than Redis answers on 6379 in the index.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption
Insufficient
Hype gap+15
Incentives35
Confidence40
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Two queries were run against ZoomEye's international dataset on 2026-09-27 with the default all asset scope.

    ReportedSupportedSource: dev.to postView cited source
  2. [2]

    The query app="Redis" returned 142 matching services.

    ReportedSupportedSource: dev.to postView cited source
  3. [3]

    The query port="6379" returned 4,937,184 matching services.

    ReportedSupportedSource: dev.to postView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 9, 2026

    Redis: 142 Product Matches Beside 4.9 Million Answers on Port 6379

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories