DEV Community

kozhevniko
kozhevniko

Posted on

Small Numbers, Real Findings: AWX, NiFi, Pulsar and CockroachDB

Small Numbers, Real Findings: AWX, NiFi, Pulsar and CockroachDB

ZoomEye queries on 26 September 2026 returned 6,087 matches for app="Apache NiFi", 5,732 for app="CockroachDB", 8 for app="AWX" and zero for app="Apache Pulsar". This set is a reminder that exposure counts do not rank risk, and that a small number can still describe a system worth protecting carefully.

Context and method

The counts come from single ZoomEye queries executed through the search API on 26 September 2026 at 00:38 China Standard Time, configured with page 1, page size 1 and sub_type all. Page size limits the records returned in a response, so each figure is the platform's overall match total for that dork.

Reading a count of eight

The AWX result is the most instructive. AWX is the upstream project behind Ansible Automation Platform, and it exists to run automation jobs across an estate. Its database holds inventories, credentials, job templates and often the secrets that let a playbook authenticate to the systems it manages.
A count of eight means eight hosts on the public internet answered to that fingerprint. If any of those eight is a production automation controller with weak authentication, the practical consequence is control over every system the controller manages. Volume is one input to prioritisation, not the basis for it. For a platform whose purpose is to hold credentials for everything else, eight is a number that deserves a look instead of a dismissal.

The two mid-sized results

Apache NiFi at 6,087 and CockroachDB at 5,732 sit in a middle range that reflects both deployment scale and fingerprintability. NiFi is a data flow tool, often used for ingestion pipelines that move data between systems. It provides a web interface with a rich feature set, including the ability to define processors that manipulate data as it passes through.
CockroachDB is a distributed SQL database. It presents a web console for cluster administration alongside its SQL interface, which is likely what the fingerprint detects. An exposed database console is a serious finding, because console access typically includes the ability to create users and query data directly.

What a zero tells you, and what it does not

Apache Pulsar returned zero matches. That result describes ZoomEye's fingerprint database and the product's identifiable responses, not the state of any organisation's messaging estate. A product can be widely deployed inside private networks and still produce no internet-wide matches, which is the expected outcome for a well-placed internal service.
The useful conclusion from a zero is procedural. It means the measurement cannot substitute for an internal inventory, and that a security team should not treat the absence of a match as evidence that nothing needs attention. The most carefully placed systems are the ones an external scan will never see.

Implications and next steps

Prioritise by what a system controls, then by exposure. An automation controller or a cluster console that can reach everything else is a high-consequence target regardless of how few instances exist, so start there and work downward through the estate.
For each of these four, the immediate question is authentication. NiFi and CockroachDB both support authentication and should have it enabled, with the administrative interface restricted to internal networks. For AWX, confirm that the controller is not reachable from outside the automation network and that job credentials are scoped per environment rather than shared across production and test.
Where a platform is deployed internally and no external match exists, verify that placement deliberately rather than assuming it, because a firewall rule added for a migration is the usual way an internal service becomes an external one.

Scope and limitations

These are point-in-time fingerprint counts from ZoomEye's vantage points. They include hosting provider ranges, laboratory and research clusters, and honeypot infrastructure, and they count each reachable node separately. A zero result means no fingerprints were identified at that moment and does not establish that a product is absent from any given network. Nothing here measures exploitation, patching state or authentication configuration.

References

  • ZoomEye search API results for app="Apache NiFi", app="CockroachDB", app="AWX" and app="Apache Pulsar", collected 26 September 2026.

Top comments (0)