Port 3306: MySQL / MariaDB

MySQL and MariaDB database connections. Exposed databases are found within hours and brute-forced or wiped for ransom. Bind to 127.0.0.1 or a private network.

  • Free
  • No Sign-Up
  • Runs in Your Browser

Examples:

Ports

1 of 41

Port Lookup

Port 3306 at a glance

Port3306
ProtocolTCP
ServiceMySQL / MariaDB
Open to the Internet?No, keep it on a private network
See What Is Listeningss -lntup | grep ':3306 '
Test From Outsidenc -zv your-server 3306
Block with UFWufw deny 3306/tcp
Block with nftablesnft add rule inet filter input tcp dport 3306 drop

MySQL / MariaDB uses TCP port 3306. MySQL and MariaDB database connections.

Exposed databases are found within hours and brute-forced or wiped for ransom. Bind to 127.0.0.1 or a private network.

If ss shows something listening on port 3306 on a public address, bind it to 127.0.0.1 or a private interface in the service's own configuration, and drop the port in the firewall as well.

Questions

What is port 3306 used for?
MySQL / MariaDB. MySQL and MariaDB database connections.
Is it safe to open port 3306?
No, keep it on a private network. Exposed databases are found within hours and brute-forced or wiped for ransom. Bind to 127.0.0.1 or a private network.
How do I check if port 3306 is open?
On the server, ss -lntup | grep ':3306 ' shows what is listening. From another machine, nc -zv your-server 3306 shows whether the firewall lets it through.
How do I block port 3306?
With UFW: ufw deny 3306/tcp. With nftables, add a drop rule for dport 3306 in your input chain.

Abuse from open ports on your VMs?

Frabs spots amplification, scans and floods leaving any VM and stops them, without touching your firewall.