Skip to main content

Port Details

Port
1434
Transport
UDP
Service
SQL Server Browser
IANA service name
ms-sql-m
Range
User port (1024-49151)
Related ports

Security Exposure

The Browser answers unauthenticated SQL Server Resolution Protocol requests and returns instance ports and pipe names to anyone who can reach UDP 1434. In SQL Server 2000 the same port served the Resolution Service, whose buffer overruns were fixed in MS02-039; Microsoft noted that patch protects against the SQL Slammer worm and that blocking port 1434 at the firewall, if feasible, mitigates the risk.

Hardening

  • +Block UDP 1434 at the internet edge and allow it only from client networks that need instance discovery.
  • +Disable SQL Server Browser where all instances use fixed, known ports.
  • +Set the HideInstance flag on instances that should not be advertised.
  • +Keep SQL Server and its components patched.

Monitoring

Alert on UDP 1434 traffic from outside internal client ranges and on hosts that unexpectedly answer on 1434.

Tools for Auditing and Monitoring SQL Server Browser

Penetration Testing Tools

Python library of classes and example tools for the construction, parsing, and interaction with Windows and Active Directory network protocols.

LicenseModified Apache-1.1 (custom; see repo LICENSE)
PlatformLinux, macOS, Windows

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nessus

Commercial
Vulnerability Scanning

Tenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.

LicenseProprietary
PlatformLinux, Windows, Web

Frequently Asked Questions

Do I need port 1434 open for SQL Server?→

Only when clients must find named instances that use dynamic ports. Microsoft documents opening UDP 1434 for the Browser alongside TCP 1433 for the default instance.

What was the SQL Slammer worm?→

A worm that spread in 2003 through SQL Server computers, generating heavy 1434/udp traffic according to CERT advisory CA-2003-04. Microsoft states the MS02-039 patch protects SQL Server 2000 and MSDE 2000 against it.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 1434 is not guaranteed to be SQL Server Browser. Exploited-in-the-wild data from the CISA KEV catalog (CC0).