Port 3306: MySQL database server
TCP 3306 is the default port of the MySQL server, and MySQL's security guidelines use it when explaining how to test for exposure. Applications connect to MySQL databases on this port.
Port Details
Security Exposure
Shadowserver's scans found over 3.6 million MySQL servers reachable on IPv4 and IPv6 in 2022, and it rates accessible MySQL instances as high severity. A reachable server invites password guessing against database accounts and exposes the server to any authentication or protocol flaw. MySQL's guidelines warn that an account such as root without a password lets anyone connect with full privileges.
Hardening
- +Put MySQL behind a firewall or in a DMZ, as MySQL's security guidelines recommend, and allow 3306 only from application servers.
- +Set strong passwords on all accounts, including root, and never grant privileges to all hosts.
- +Require TLS for client connections that cross untrusted networks.
- +Review account privileges with SHOW GRANTS and revoke what applications do not need.
Monitoring
Alert on connections to 3306 from addresses outside the application tier and on bursts of failed logins in the MySQL error log. External scan feeds such as Shadowserver reports flag servers that answer from the internet.
Tools for Auditing and Monitoring MySQL
sqlmap
Free / CommercialAutomated penetration testing tool that detects and exploits SQL injection flaws to assess database security configurations.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
OPENVAS
Free / CommercialFull-featured vulnerability scanner for identifying security flaws, missing patches, and weak configs across network hosts.
Related Tool Categories
Frequently Asked Questions
Should port 3306 be open to the internet?→
Generally no. Shadowserver states that it is unlikely a MySQL server needs to accept connections from the internet, and MySQL recommends placing the server behind a firewall.
How can I check whether port 3306 is exposed?→
MySQL's security guidelines suggest testing from an untrusted host with nmap or a TCP connection attempt to port 3306. A refused or hanging connection indicates the port is blocked.
Is MySQL port 3306 TCP or UDP?→
MySQL clients connect over TCP on 3306. IANA lists both transports for the mysql registration.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 3306 is not guaranteed to be MySQL. Exploited-in-the-wild data from the CISA KEV catalog (CC0).