Skip to main content

Kafka - 9092

Apache Kafka is a distributed event-streaming platform (a durable, partitioned message bus). Applications use it as the backbone between producers and consumers - which makes it a high-value target: it often carries PII, tokens, and the messages that drive downstream processing.

Default Ports​

PortPurpose
9092Broker client listener (PLAINTEXT or SASL_PLAINTEXT)
9093KRaft controller listener (controller.quorum.*)
9094Often a second listener (e.g. SASL_PLAINTEXT, SSL)
8083Kafka Connect REST API
9999 / JMXJMX management

Fingerprinting​

  • The broker responds to a Kafka ApiVersions request; kafka-broker-api-versions.sh prints the version banner.
  • nmap -sV -p9092 TARGET may only say "tcpwrapped" without a client handshake.
  • A SASL_PLAINTEXT listener requires a SASL handshake before normal requests.
  • Look for the process and config on the host: ps aux | grep -i kafka, server.properties.

Enumeration (no auth / permissive ACLs)​

The bundled CLI tools talk to the broker directly. If ACLs are disabled or permissive (allow.everyone.if.no.acl.found=true, no authorizer), you can list and read everything:

# List topics
kafka-topics.sh --bootstrap-server TARGET:9092 --list
# Describe a topic (partitions, replicas, configs)
kafka-topics.sh --bootstrap-server TARGET:9092 --describe --topic <topic>
# Consumer groups (and lag)
kafka-consumer-groups.sh --bootstrap-server TARGET:9092 --list
# Consume messages from the beginning
kafka-console-consumer.sh --bootstrap-server TARGET:9092 --topic <topic> --from-beginning

Reading a topic often yields credentials, tokens, session data, or the raw data an app ingests. Writing to a topic injects data into every downstream consumer.


SASL Credentials​

Kafka SASL_PLAINTEXT commonly uses PLAIN, with credentials stored in plaintext in server.properties or a JAAS file:

sasl.enabled.mechanisms=PLAIN
listener.name.sasl_plaintext.plain.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required \
user_svc="Coolpass123@";

Common config locations:

/opt/kafka*/config/server.properties
/etc/kafka/server.properties
/opt/kafka*/config/kafka_server_jaas.conf
/etc/kafka/kafka_server_jaas.conf
info

Client configs (producer/consumer *.properties, .env, service unit EnvironmentFile=) also carry SASL usernames/passwords. See Exploitation & Lateral Movement → All About Credentials for config-driven secret harvesting.

danger

Credential reuse is common: the SASL/JAAS username is frequently the service account name and the password is reused for the OS login. Try the SASL password against ssh, su, and other services on the host.


Attack Surface​

  • Read sensitive topics - PII, JWTs/API keys, internal events, secrets other services publish.
  • Publish forged messages - inject into a topic that a downstream service parses. Example: if a consumer parses XML, a crafted message triggers XXE in the consumer (see Web Hacking → XML Attacks → XXE). This is how a broker foothold becomes application/RCE.
  • Unauthenticated JMX - brokers are often started with -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false. JMX over a reachable port is a well-known RCE primitive (mbean/javax.script).
  • Kafka Connect (8083) - the REST API can create/modify connectors; malicious connector configs/plugins have led to RCE.
  • Data-pipeline metadata - a downstream database's Kafka table engine (e.g. ClickHouse) can reveal broker addresses and topic names even when the broker itself is internal. See Web-Based Platforms → ClickHouse.
  • Broker on a random published port - an internal localhost:9092 listener is sometimes published externally on a high random port; don't assume it's closed just because 9092 is.

Remediation / Secure Coding​

  1. Enable authentication - SASL/SCRAM (or mTLS) for clients; never run production brokers with PLAINTEXT client listeners on untrusted networks.
  2. Enable the authorizer with ACLs and set allow.everyone.if.no.acl.found=false. Restrict which principals may produce/consume each topic.
  3. Never store plaintext credentials in server.properties/JAAS - externalize to a secret manager; restrict file permissions (chmod 600, dedicated service account).
  4. Do not reuse service credentials for OS accounts (/etc/passwd vs SASL). Rotate and scope them independently.
  5. Secure JMX - require authentication and SSL, or disable remote JMX; bind to localhost.
  6. Network-segment the broker; do not publish it to the internet. Bind listeners to internal interfaces only.
  7. Treat topic contents as untrusted input downstream - consumers must parse defensively (e.g. disable DTD/entities in XML parsers) because anyone who can produce may be hostile.

References​