DEV Community

yutianle
yutianle

Posted on

SaltStack at 60,140 observed assets: remote execution as a standing capability

SaltStack at 60,140 observed assets: remote execution as a standing capability

SaltStack is a configuration management and remote execution system. Its central feature is that it can run a command on every managed host at once, and it is designed to do so. A ZoomEye query for app="SaltStack" returned 60,140 matching assets on 2026-10-03 UTC. The number is large, and the capability behind it is the reason to look at it closely.

The two ports that matter

Salt runs on a master-minion architecture. The master listens on two ports by default, and they are the whole security surface.
Port 4505 carries the publisher, the channel over which the master broadcasts commands to all connected minions. Port 4506 carries the request server, which minions use to return results and which also handles file transfers. Both use ZeroMQ over TCP, and both use certificate-based authentication.
The important detail is that the publisher is a broadcast channel. Any process that can subscribe to 4505 receives every command the master sends, and any process that can publish to 4505 can issue a command that every connected minion will execute. The minions verify the master's public key, which is why an attacker needs more than network reachability to publish. It is also why the master's key pair is the boundary.
Because both ports are ZeroMQ rather than HTTP, they are harder to fingerprint than a web interface, and a measurement based on an application signature captures the population that the fingerprint engine could identify. The 60,140 is a floor.

Why the exposure class is different from a web application

A web application exposed to the internet accepts requests and returns responses. The authority of the exposed service is bounded by what the application does.
Salt's authority is not bounded that way. The master holds credentials for the minions: the private key that signs commands, the file server root that distributes configuration, and often the pillar data that contains secrets. The minions hold the master's public key and accept commands that are signed with it.
An attacker who obtains the master's private key, or who reaches a master's local filesystem, can issue a command to the entire fleet. That is a legitimate Salt feature and it is the reason a Salt master is a tier-zero asset. The same authority is what makes the minion-side key verification the only thing standing between a reachable publisher and fleet-wide execution.
There is a documented history here. The Salt master had a run of critical issues in 2020 that were fixed in 3000.2, including an authentication bypass in the request server and a path traversal in the file server. Those were pre-authentication flaws in exactly the two ports above, and a deployment that did not upgrade kept the exposure.

What to check

Confirm that ports 4505 and 4506 are not reachable from outside the management network. These are the two ports that should never be in an internet-facing measurement. If your master appears in a query like the one used here, the network path is the first finding.
Check the master's key material. The private key is the authority for the fleet. Its file permissions, its presence in backups, and its inclusion in any image or snapshot are all worth a review.
Check the minion-side configuration. master_fingerprint in the minion configuration pins the master's public key fingerprint. A deployment that does not set it accepts the key it is given on first contact, which is a trust-on-first-use model.
Check for the auto-accept settings. auto_accept: True on the master signs any minion key that presents itself. open_mode on a minion allows it to be commanded by any master. Both are configuration options that exist for bootstrapping and are frequently left on.
Check the grain and pillar data. Pillar is where secrets live, and it is served from the master. A master that is reachable is a file server for its pillar tree.
Use ZoomEye against your own ranges. Combining the application fingerprint with org= or cidr= answers whether any of your infrastructure is reachable. The search link for the query used here is recorded in the manifest.

Reading the count

60,140 observable SaltStack assets says that a remote execution platform is widely reachable. The count does not identify which deployments verify minion keys, which use auto-accept, or which are reachable only because a management network leaked. Those are the questions the count makes askable, and they are the same questions a fleet owner can answer for their own estate in an afternoon.

References

  • Salt Project documentation, architecture and master-minion communication.
  • Salt Project security advisory archive, including the 3000.2 fixes.
  • Salt Project documentation, master_fingerprint, auto_accept and open_mode.
  • ZoomEye search interface documentation.

Top comments (0)