Kafka - 9092
Apache Kafka is a distributed event-streaming platform (a durable, partitioned message bus). Applications use it as the backbone between producers and consumers - which makes it a high-value target: it often carries PII, tokens, and the messages that drive downstream processing.
Default Ports
| Port | Purpose |
|---|---|
9092 | Broker client listener (PLAINTEXT or SASL_PLAINTEXT) |
9093 | KRaft controller listener (controller.quorum.*) |
9094 | Often a second listener (e.g. SASL_PLAINTEXT, SSL) |
8083 | Kafka Connect REST API |
9999 / JMX | JMX management |
Fingerprinting
- The broker responds to a Kafka
ApiVersionsrequest;kafka-broker-api-versions.shprints the version banner. nmap -sV -p9092 TARGETmay only say "tcpwrapped" without a client handshake.- A
SASL_PLAINTEXTlistener requires a SASL handshake before normal requests. - Look for the process and config on the host:
ps aux | grep -i kafka,server.properties.
Enumeration (no auth / permissive ACLs)
The bundled CLI tools talk to the broker directly. If ACLs are disabled or permissive (allow.everyone.if.no.acl.found=true, no authorizer), you can list and read everything:
# List topics
kafka-topics.sh --bootstrap-server TARGET:9092 --list
# Describe a topic (partitions, replicas, configs)
kafka-topics.sh --bootstrap-server TARGET:9092 --describe --topic <topic>
# Consumer groups (and lag)
kafka-consumer-groups.sh --bootstrap-server TARGET:9092 --list
# Consume messages from the beginning
kafka-console-consumer.sh --bootstrap-server TARGET:9092 --topic <topic> --from-beginning
Reading a topic often yields credentials, tokens, session data, or the raw data an app ingests. Writing to a topic injects data into every downstream consumer.
SASL Credentials
Kafka SASL_PLAINTEXT commonly uses PLAIN, with credentials stored in plaintext in server.properties or a JAAS file:
sasl.enabled.mechanisms=PLAIN
listener.name.sasl_plaintext.plain.sasl.jaas.config=org.apache.kafka.common.security.plain.PlainLoginModule required \
user_svc="Coolpass123@";
Common config locations:
/opt/kafka*/config/server.properties
/etc/kafka/server.properties
/opt/kafka*/config/kafka_server_jaas.conf
/etc/kafka/kafka_server_jaas.conf
Client configs (producer/consumer *.properties, .env, service unit EnvironmentFile=) also carry SASL usernames/passwords. See Exploitation & Lateral Movement → All About Credentials for config-driven secret harvesting.
Credential reuse is common: the SASL/JAAS username is frequently the service account name and the password is reused for the OS login. Try the SASL password against ssh, su, and other services on the host.
Attack Surface
- Read sensitive topics - PII, JWTs/API keys, internal events, secrets other services publish.
- Publish forged messages - inject into a topic that a downstream service parses. Example: if a consumer parses XML, a crafted message triggers XXE in the consumer (see
Web Hacking → XML Attacks → XXE). This is how a broker foothold becomes application/RCE. - Unauthenticated JMX - brokers are often started with
-Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false. JMX over a reachable port is a well-known RCE primitive (mbean/javax.script). - Kafka Connect (8083) - the REST API can create/modify connectors; malicious connector configs/plugins have led to RCE.
- Data-pipeline metadata - a downstream database's
Kafkatable engine (e.g. ClickHouse) can reveal broker addresses and topic names even when the broker itself is internal. SeeWeb-Based Platforms → ClickHouse. - Broker on a random published port - an internal
localhost:9092listener is sometimes published externally on a high random port; don't assume it's closed just because9092is.
Remediation / Secure Coding
- Enable authentication - SASL/SCRAM (or mTLS) for clients; never run production brokers with
PLAINTEXTclient listeners on untrusted networks. - Enable the authorizer with ACLs and set
allow.everyone.if.no.acl.found=false. Restrict which principals may produce/consume each topic. - Never store plaintext credentials in
server.properties/JAAS - externalize to a secret manager; restrict file permissions (chmod 600, dedicated service account). - Do not reuse service credentials for OS accounts (
/etc/passwdvs SASL). Rotate and scope them independently. - Secure JMX - require authentication and SSL, or disable remote JMX; bind to localhost.
- Network-segment the broker; do not publish it to the internet. Bind listeners to internal interfaces only.
- Treat topic contents as untrusted input downstream - consumers must parse defensively (e.g. disable DTD/entities in XML parsers) because anyone who can produce may be hostile.