deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

Port 2375 scans overstate Docker exposure, ZoomEye fingerprint narrows it to 1,032 hosts

A dev.to analysis of the CARBONATO advisory shows why counting open port 2375 endpoints misstates Docker risk: only 1,032 of roughly 1.4 million assets fingerprint as Docker on that port.

Port 2375 scans overstate Docker exposure, ZoomEye fingerprint narrows it to 1,032 hosts

The advisory, and how it gets over-read

On 30 September 2026, Singapore's Cyber Security Agency and SingCERT published an advisory on the CARBONATO botnet campaign, which targets Docker daemons left reachable on the network. The advisory names TCP port 2375, the default port for Docker's unencrypted Remote API, as the typical way in.

A dev.to analysis of the advisory argues that this detail invites a specific mistake: treating an open port 2375 as proof that Docker's Remote API is exposed without authentication. Teams that make that leap, the author writes, overcount their own risk and aim their response effort at the wrong targets.

The measurement

To size the gap, the author queried the internet scanning service ZoomEye on 30 September 2026. A port-only search for 2375 returned 1,437,638 assets. Adding ZoomEye's Docker application fingerprint to the same search returned 1,032.

That is roughly three orders of magnitude apart, and the reason is structural. Ports are conventions: Docker's Remote API uses 2375 by default, but nothing reserves the number, and unrelated software can bind it. A port-only query cannot distinguish a Docker daemon from any other service that happens to listen on the same value. ZoomEye's application fingerprint adds an identification step, classifying the service behind the port, so its result describes Docker assets rather than traffic on a number.

Layers within the Docker population

Even among Docker-identified assets, the population shifts depending on which fingerprint is used. The analysis lists five counts from the same queries:

  • app="Docker" — 13,246 assets ZoomEye identifies as Docker, however they are reached
  • app="Docker" combined with service="http" — 9,477
  • http.header.server="Docker" — 59,902, a weaker and broader signal based on Server headers
  • banner="Docker" — 354,334, the widest banner-text match
  • app="Docker" combined with port="2375" — 1,032

Each line answers a different question about the relationship between the asset and the product. Only the last constrains both the product identity and the specific exposure path the CARBONATO advisory describes.

How teams should respond

The analysis does not dismiss port queries. When an incident is about an exposed service, a port query legitimately documents the size of the listening surface. The problem is how the number is presented: "1,437,638 assets respond on port 2375" is accurate, while "1,437,638 Docker hosts are exposed" is not.

The recommended practice is to label the query, run the fingerprint search alongside the port search, and report both figures. ZoomEye supports that comparison because it exposes product and header fields next to port fields, so one interface can answer both the narrow and broad versions of the question.

The author adds two caveats. The counts describe observed exposure at the moment of the query, executed between 17:16 and 17:18 UTC on 30 September 2026, and they do not confirm that any asset actually accepts unauthenticated API calls, nor that it has been compromised. For remediation, the analysis points to Docker's own documentation on protecting the daemon socket.

Why it matters

Defenders can only scope a response as precisely as they measure the problem. CARBONATO exploits a specific misconfiguration — Docker's Remote API reachable without authentication — so the population that matches the advisory is the roughly 1,000 fingerprinted assets on port 2375, not the 1.4 million endpoints that merely answer on that number. Overcounting inflates risk registers, wastes triage time and can trigger broad shutdowns of services that were never vulnerable in the first place.

The data cuts the other way too: the 13,246 assets identified as Docker regardless of port are a reminder that exposure is not confined to the default port. The lesson is not that one query is right and the others wrong, but that each count answers a different question, and incident response depends on knowing which question you actually asked.

  • #docker
  • #security
  • #cloud-security
  • #zoom-eye
  • #network-scanning

Related posts