Port 1434: Microsoft SQL Server Browser (Resolution Service)
UDP 1434 is claimed by the SQL Server Browser service at startup. Clients send a UDP query to 1434, and the Browser answers with the TCP port or named pipe for the requested instance. It starts automatically for named instances, SQL Server Express and clusters.
Port Details
Security Exposure
The Browser answers unauthenticated SQL Server Resolution Protocol requests and returns instance ports and pipe names to anyone who can reach UDP 1434. In SQL Server 2000 the same port served the Resolution Service, whose buffer overruns were fixed in MS02-039; Microsoft noted that patch protects against the SQL Slammer worm and that blocking port 1434 at the firewall, if feasible, mitigates the risk.
Hardening
- +Block UDP 1434 at the internet edge and allow it only from client networks that need instance discovery.
- +Disable SQL Server Browser where all instances use fixed, known ports.
- +Set the HideInstance flag on instances that should not be advertised.
- +Keep SQL Server and its components patched.
Monitoring
Alert on UDP 1434 traffic from outside internal client ranges and on hosts that unexpectedly answer on 1434.
Tools for Auditing and Monitoring SQL Server Browser
Impacket
FreePython library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nessus
CommercialTenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.
Related Tool Categories
Frequently Asked Questions
Do I need port 1434 open for SQL Server?→
Only when clients must find named instances that use dynamic ports. Microsoft documents opening UDP 1434 for the Browser alongside TCP 1433 for the default instance.
What was the SQL Slammer worm?→
A worm that spread in 2003 through SQL Server computers, generating heavy 1434/udp traffic according to CERT advisory CA-2003-04. Microsoft states the MS02-039 patch protects SQL Server 2000 and MSDE 2000 against it.
Sources
- IANA Service Name and Port Number Registry: port 1434
- Microsoft Learn: SQL Server Browser service
- Microsoft Learn: Configure the Windows Firewall to allow SQL Server access
- Microsoft Security Bulletin MS02-039: Buffer Overruns in SQL Server 2000 Resolution Service
- Microsoft Learn: Service overview and network port requirements for Windows
- CERT Advisory CA-2003-04: MS-SQL Server Worm
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 1434 is not guaranteed to be SQL Server Browser. Exploited-in-the-wild data from the CISA KEV catalog (CC0).