Port 1433: Microsoft SQL Server Database Engine (TDS)
TCP 1433 is where the default instance of the Microsoft SQL Server Database Engine listens when TCP/IP is enabled. Named instances use dynamic ports by default, which clients look up through the SQL Server Browser on UDP 1434. Applications, reporting tools and administrators connect here.
Port Details
Security Exposure
A database listener on the internet exposes logins and data directly to remote attackers. Microsoft Defender for SQL includes alerts for suspected brute force attacks, and SQL Server Authentication is less secure than Windows Authentication.
Hardening
- +Do not expose 1433 to the internet; allow it only from application servers and admin networks.
- +Prefer Windows Authentication, which Microsoft describes as much more secure than SQL Server Authentication.
- +Encrypt client connections with TLS by configuring a server certificate.
- +Keep the sa login disabled and give any SQL logins strong, unique passwords.
- +Apply the latest SQL Server and operating system patches.
Monitoring
Enable SQL Server Audit at the server level and track failed logins. Alert on login attempts from addresses outside the application and admin ranges.
MS SQL Server Vulnerabilities
1 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability | Microsoft | 8.8 | 57.3% | KEV | 2019-07-15 |
Tools for Auditing and Monitoring MS SQL Server
Impacket
FreePython library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.
sqlmap
Free / CommercialAutomated penetration testing tool that detects and exploits SQL injection flaws to assess database security configurations.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Data loss prevention, data posture management, and sensitive data discovery and classification platforms.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.
Frequently Asked Questions
Is port 1433 TCP or UDP?→
The Database Engine listens on TCP 1433. UDP 1434 is used by the SQL Server Browser service.
Do named SQL Server instances use port 1433?→
Not by default. Microsoft states named instances use dynamic ports chosen at startup, unless configured with a fixed port.
Which vulnerabilities affect the service on port 1433?→
This database lists 1 CVE related to MS SQL Server, 1 of them confirmed as exploited by CISA. Examples: CVE-2019-1068.
Sources
- IANA Service Name and Port Number Registry: port 1433
- Microsoft Learn: Configure a server to listen on a specific TCP port
- Microsoft Learn: Configure the Windows Firewall to allow SQL Server access
- Microsoft Learn: Choose an authentication mode
- Microsoft Learn: SQL Server security best practices
- Microsoft Learn: Alerts for SQL Database and Azure Synapse Analytics
- Microsoft Learn: Configure SQL Server Database Engine for encrypting connections
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 1433 is not guaranteed to be MS SQL Server. Exploited-in-the-wild data from the CISA KEV catalog (CC0).