deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

ZoomEye data shows 3.3M hosts on WebLogic port 7001, 1M on Cassandra JMX port 7199

A dev.to analysis of ZoomEye data from 25 September 2026 counted 3,331,906 hosts answering on Oracle WebLogic's default port 7001 and 1,037,743 on Cassandra's default JMX management port 7199.

ZoomEye data shows 3.3M hosts on WebLogic port 7001, 1M on Cassandra JMX port 7199

The measurement

A post on dev.to reports two internet-scale counts taken from the ZoomEye search engine on 25 September 2026. A query for port 7001 returned 3,331,906 matching hosts; a query for port 7199 returned 1,037,743. Both searches were run with the engine's "all" sub-type and a page size of one, so the results are aggregate counts rather than host-by-host inventories.

What answers on those ports

According to the post, port 7001 is the default HTTP listener for Oracle WebLogic Server: a fresh install serves requests there, and the administration console frequently remains on the same port unless someone deliberately relocates it. Port 7199 is the default JMX remote management endpoint for Apache Cassandra, exposing a control interface to a database that holds operational state for whatever depends on it.

The author's argument is that the common thread is not either vendor but a deployment habit: the management listener ships enabled, on a predictable port, alongside the service it governs.

Why the defaults survive

Middleware installations have to work on the first attempt, the post explains, so the administrative interface is enabled from the outset. Disabling it afterwards is a separate change that carries its own testing burden, and so it rarely happens. The practical consequence is that consoles and JMX endpoints intended for a brief setup window stay reachable from networks that never needed them, sometimes for years.

A history of pre-auth code execution

Both ports have previously been associated with remote code execution that could be triggered without valid credentials, the post notes. That history is what turns a large port count from a curiosity into a risk indicator, even though the count itself proves nothing about any individual host.

What the numbers do not show

The author is careful to state that neither figure is a tally of vulnerable servers. The 7001 result includes WebLogic instances of every version and patch level, plus unrelated services that happen to bind the same port; the 7199 result covers Cassandra clusters in every configuration state. What the pair does establish is architectural: default management listeners exist on publicly reachable addresses at a scale of millions. How many of those accept unauthenticated connections is a subset that no port count can determine.

The checks operators should run

For organisations running either product, the post sets out specific questions. Is the WebLogic console on 7001 reachable from anywhere outside the administrative network? Does the Cassandra JMX endpoint on 7199 require authentication, or does it accept connections from the same networks as the application? Management-plane patching should also be reviewed separately from application patching, because middleware upgraded for business reasons often retains the console configuration it was installed with. Finally, admin interfaces should be monitored for connections from unexpected sources: traffic arriving from outside an interface's intended network is a finding in its own right, regardless of what the application's logs show.

Why it matters

The measurement quantifies a class of attack surface that routine patching does not shrink. Management consoles and JMX listeners are not the application; they are the interfaces that can halt it, redeploy it, and read everything it holds, which makes them a shortcut to full compromise when left open. Because they tend to survive normal upgrade cycles, the exposure accumulates rather than decays, and these counts suggest the resulting surface is measured in millions of hosts. For defenders, enumerating exposed management ports and treating unexpected traffic to them as an incident is far cheaper than discovering, after a breach, that one of them was the entry point.

  • #weblogic
  • #cassandra
  • #security
  • #middleware
  • #jmx

Related posts