Redis: 142 Product Matches Beside 4.9 Million Answers on Port 6379
Redis is designed to be reached by applications on a trusted network. Its security documentation is unusually direct about the consequence of exposing it: the server should be accessed only by clients on the same host or a trusted network, and protected with a firewall when it is not. A measurement of port 6379 is therefore an unusually good proxy for an exposure class, even when the product fingerprint itself returns almost nothing.
The trust model
The Redis security page describes an access control model built on protected mode, an optional password, and the rule that the server is not intended to be exposed to the internet. The recovery instructions for a compromised instance are equally direct: a reached instance allows the operator's data to be read, and where the configuration permits it, allows the server to write files.
The relevant property is that the default configuration requires no authentication on a local socket, and that authentication is opt-in for network listeners. A service reachable from an untrusted network without authentication is a data store that answers to anyone.
The measurement
Two queries were run against the international dataset on 2026-09-27 with the default all asset scope:
app="Redis"
Observed result: 142 matching services.
port="6379"
Observed result: 4,937,184 matching services.
The product fingerprint result is small enough that the dataset's coverage for this product can be described as limited for exposure-scoping purposes. The port result is the opposite: nearly five million services answer on 6379.
The same caveat as any port observation applies. The count includes software other than Redis that listens on 6379, and it describes reachability from the scanning infrastructure. The count excludes Redis instances on non-standard ports and instances bound to a local interface only, which is the intended deployment.
Why port-level measurement works here
For products with a well-known default port and a documented prohibition on internet exposure, the port is a reasonable identifier even without a product fingerprint. Two properties make it reasonable for Redis specifically:
The default port is stable across versions and distributions, and it is not commonly reused by unrelated software in the index.
The security guidance is unambiguous, so the population of interest is defined by the exposure rather than by a version or a vulnerability.
A count of five million answers on the port does not mean five million exposed data stores. It means five million services where the question, is this an exposed data store, is worth asking of the owner.
Checks that decide whether a service belongs to the risk population
For each service the organisation owns that answers on 6379:
- Confirm the bind address and whether it is the local interface or a network interface.
- Confirm whether a password is configured and whether protected mode is enabled.
- Confirm whether the firewall rule is limited to the application hosts that require access.
- Confirm that the command rename or disable configuration is applied where the deployment permits command-level restriction.
- Confirm that persistence files are not written to a location an unauthenticated client could influence.
Reporting the two numbers together
The comparison is a useful habit for report writing: state the product fingerprint, state the port, and state which one the analysis relies on and why. Both query shapes are available from https://www.zoomeye.ai/, and for Redis the port scope is the one that produces a reviewable candidate list for the organisation's own ranges.
ZoomEye's combination of a port scope and a bounded search interface is what allows the two counts to be produced and compared without leaving the tool, which is the practical reason to record both.
References
- Redis documentation, Security. https://redis.io/docs/latest/operate/oss_and_stack/management/security/
- Redis documentation, Redis security model and access control. https://redis.io/docs/latest/operate/oss_and_stack/management/security/acl/
- ZoomEye. https://www.zoomeye.ai/
Top comments (0)