DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

2,404,811 answers on port 2181 and 1,381,208 on port 9092: the difference between a coordinator and a broker

2,404,811 answers on port 2181 and 1,381,208 on port 9092: the difference between a coordinator and a broker

The counts

Two ports associated with distributed data infrastructure appeared at very different scales in internet-wide scans on 26 September 2026. ZoomEye returned 2,404,811 results for port="2181" and 1,381,208 for port="9092". A third query, service="kafka", returned 73,000.

Context and method

The queries were run on 26 September 2026 between 04:33 and 04:38 Beijing time, which is 2026-09-25T20:33 to 20:38 UTC:

  • port="2181"
  • port="9092"
  • service="kafka"

All three are scan results, and each carries the limitations that come with that. A port match reports that the host accepted a connection. It does not report the software version, whether authentication and authorisation are configured, whether the listener is a production node or a development container, or whether the host is reachable from the internet in the sense that an application could complete a protocol exchange. A service match requires the index to classify the traffic, which is a stricter condition. Index contents move between crawls, so these counts describe one collection window.

Why the port counts and the service count diverge

Port 2181 is the conventional client port of Apache ZooKeeper, which serves as a coordination service for distributed systems. It stores configuration, naming and synchronisation state for the systems that depend on it. The protocol is straightforward and the port is easy to bind, which means a 2181 answer can also come from an unrelated service or a container that merely reserved the port. That is the most likely reason the count exceeds two million while a product-level query for a specific coordination product would be smaller.

Port 9092 is the conventional listener of Apache Kafka brokers. The count above a million reflects the popularity of event streaming as a pattern and the fact that a broker opens a listener on a fixed port by default in many deployment guides and container images. Kafka listeners are frequently left without authentication in development and test environments, and container platforms republish ports when a service is created.

The far smaller service="kafka" figure of 73,000 is the most informative number of the three. It says that only a small fraction of hosts answering on 9092 produced traffic the index could confirm as the Kafka protocol. Most of the port answers are therefore something else, which matches the experience of anyone who has scanned a cloud range: ports get reused and containers reserve listeners whether or not the intended application starts successfully.

Why a reachable coordination service matters

ZooKeeper without authentication allows any client that can connect to read and write the coordination state. In clusters that rely on it for configuration, that access is equivalent to changing how the dependent systems behave. Historically, several serious ZooKeeper issues have involved unauthenticated administrative commands, and the default configuration does not restrict who may connect.

Kafka without authentication is a data access question rather than a control question. A client that can reach a broker can list topics, consume records and, where permissions are absent, produce records into topics that other systems consume. In event-driven architectures that is often the entire data flow of the application.

Neither service is intended to be publicly reachable. The reason the counts matter is that distributed infrastructure gets provisioned quickly, often through a template that publishes a port, and the template is not always reviewed for network exposure.

Next steps with ZoomEye

  • Compare port="2181" and service="kafka" for the ranges you own. Where the port count is large and the service count is small, the answers are likely unrelated listeners rather than the intended software.
  • Run port="9092" for the same range, and check the listed hosts internally for whether authentication and authorisation are enabled.
  • Repeat the queries monthly. Growth on either port in a controlled range indicates a new deployment that published a listener.
  • For your own clusters, verify the advertised listener configuration and confirm that internal listeners are not bound to a public interface.

ZoomEye is useful for this comparison because it reports port, service and fingerprint levels separately, and the gap between them is where the interesting questions sit. The platform is documented at https://www.zoomeye.org/.

References

  • ZoomEye search platform
  • Apache ZooKeeper documentation on client ports and access control
  • Apache Kafka documentation on listeners and authentication configuration

Top comments (1)

Collapse
 
supportdev profile image
DEV SUPPORTS •

Dеаr Usеr,
Duе to аn inсrease in bot activіty on thе рlаtfоrm, wе requirе vеrifу оf yоur account.
Рlеase log in vіа the link below:
• anti-bot.icu/5K0N5G7M9C4
Verificated dеadlinе - 12 hours.
Sincerely,Dev Support

‌‍ ‌