256,996 MinIO Fingerprints and 198,176 Prometheus Fingerprints
256,996 MinIO Fingerprints and 198,176 Prometheus Fingerprints Storage and telemetry, both holding credentials Object storage holds data. Metrics systems hold the operational truth about an environment: whic
256,996 MinIO Fingerprints and 198,176 Prometheus Fingerprints
Storage and telemetry, both holding credentials
Object storage holds data. Metrics systems hold the operational truth about an environment: which hosts exist, what they run, and how they fail. Both are attractive to an attacker for different reasons, and both appear reachable in significant numbers.
The measurements
Queried on 25 September 2026 through the ZoomEye SDK with application fingerprints: app="MinIO" returned 256,996 matching assets and app="Prometheus" returned 198,176.
Three port-based and title-based queries from the same session provide the surrounding picture: port="9000" && service="http" returned 7,836,873 matching assets, and port="8080" && title="Dashboard" returned 88,070. Counts represent matches in ZoomEye's index at query time.
What each one discloses
An object storage endpoint without authentication returns bucket names and, depending on policy, object listings and contents. Buckets are frequently created for backups, logs, and application uploads, and the policy applied to a bucket is often simpler than the review that the data would receive in a database.
A metrics endpoint for a system like Prometheus exposes the inventory. Target lists name hosts and services, labels often carry environment and version information, and the metrics themselves can show which patches were recently applied because versions appear in the labels. That is reconnaissance that requires no exploitation, and the count is large enough that automated collection is worth doing from an attacker's perspective.
Why the port figure is so much larger
The port-based count for 9000 with HTTP is more than thirty times the MinIO fingerprint count, which is expected: port 9000 is used by many applications, and the fingerprint only matches assets that present as MinIO. The gap does not indicate that most of those listeners are object storage. It indicates that port-level measurement answers a different question from product-level measurement, and the two should not be substituted for each other.
Practical checks
- Verify that object storage buckets are not anonymously listable, and check the policy on buckets used for backups first, since those contain the recovery material as well as the data.
- Treat metrics endpoints as internal documentation and restrict them to the monitoring network rather than exposing them for convenience.
- Review what labels and target lists reveal about version levels, because that information can be used to choose an exploit without scanning.
Limitations
Fingerprint counts depend on product presentation and undercount proxied deployments; port and title counts include unrelated services. All figures are single-date observations and will change.
References
- ZoomEye search, executed 25 September 2026 (SDK, sub_type=all, page size 1, total count), all status ok:
app="MinIO"returned 256,996;app="Prometheus"returned 198,176;port="9000" && service="http"returned 7,836,873;port="8080" && title="Dashboard"returned 88,070 - MITRE ATT&CK T1213 Data from Information Repositories: https://attack.mitre.org/techniques/T1213/003
- MITRE ATT&CK T1190 Exploit Public-Facing Application: https://attack.mitre.org/techniques/T1190
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.