Skip to main content

Port Details

Port
3306
Transport
TCP
Service
MySQL
IANA service name
mysql
Range
User port (1024-49151)

Security Exposure

Shadowserver's scans found over 3.6 million MySQL servers reachable on IPv4 and IPv6 in 2022, and it rates accessible MySQL instances as high severity. A reachable server invites password guessing against database accounts and exposes the server to any authentication or protocol flaw. MySQL's guidelines warn that an account such as root without a password lets anyone connect with full privileges.

Hardening

  • +Put MySQL behind a firewall or in a DMZ, as MySQL's security guidelines recommend, and allow 3306 only from application servers.
  • +Set strong passwords on all accounts, including root, and never grant privileges to all hosts.
  • +Require TLS for client connections that cross untrusted networks.
  • +Review account privileges with SHOW GRANTS and revoke what applications do not need.

Monitoring

Alert on connections to 3306 from addresses outside the application tier and on bursts of failed logins in the MySQL error log. External scan feeds such as Shadowserver reports flag servers that answer from the internet.

Tools for Auditing and Monitoring MySQL

sqlmap

Free / Commercial
Penetration Testing Tools

Automated penetration testing tool that detects and exploits SQL injection flaws to assess database security configurations.

LicenseGPL-2.0-or-later (with sqlmap clarifications and exceptions)
PlatformLinux, macOS, Windows

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

OPENVAS

Free / Commercial
Vulnerability Scanning

Full-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.

LicenseGPL-2.0-only (C scanner); GPL-2.0-or-later WITH OpenSSL-exception (Rust)
PlatformLinux

Frequently Asked Questions

Should port 3306 be open to the internet?→

Generally no. Shadowserver states that it is unlikely a MySQL server needs to accept connections from the internet, and MySQL recommends placing the server behind a firewall.

How can I check whether port 3306 is exposed?→

MySQL's security guidelines suggest testing from an untrusted host with nmap or a TCP connection attempt to port 3306. A refused or hanging connection indicates the port is blocked.

Is MySQL port 3306 TCP or UDP?→

MySQL clients connect over TCP on 3306. IANA lists both transports for the mysql registration.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 3306 is not guaranteed to be MySQL. Exploited-in-the-wild data from the CISA KEV catalog (CC0).