111 and 2049: RPC and NFS Endpoints in an Internet-Facing Population
111 and 2049: RPC and NFS Endpoints in an Internet-Facing Population Services that were never meant to leave the data centre Some protocols exist to make a private network work. Portmapper and NFS are the clearest examples: they assume a trusted network, they historically relied on host-based access control rather than authentication, and they have no business being reachable from the internet.…
Services designed for a trusted network environment, such as Portmapper and NFS, are seen as a threat when exposed to the internet. Measurement shows that many internet-facing assets have RPC and NFS endpoints listening on ports that should not be reachable from the outside. Port 6379, associated with Redis, was found on 4,936,184 hosts, while port 11211 (memcached) was observed on 1,128,965 hosts.
Ports 2379 (etcd client API) and 8500 (Consul HTTP API) were reachable on 1,528,526 and 1,711,447 hosts respectively. These ports were chosen due to their historically insecure default configurations. Redis and memcached caches often accept unauthenticated connections, while the etcd API holds critical cluster state and Consul exposes service information.
The assumption of a trusted network is no longer valid when these services are reachable from the internet, exposing potential data breaches and code execution vulnerabilities. Instead of counting these ports, it is recommended to verify their reachability from untrusted networks and remove accessibility where possible. For services that must remain accessible, ensure authentication is enforced and that sensitive data is not stored in these systems.
This analysis highlights the importance of understanding the inherent risks of exposing trusted network services to the public internet.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.