Description
Common defaults include MySQL 3306, PostgreSQL 5432, Oracle 1521, and SQL Server 1433. Ports can help identify a service, but a default port does not itself publish the database or bypass authentication. Risk depends on network access, authentication, and encryption.
Potential impact
- Overly broad network permissions can increase unwanted connections and authentication attacks.
- Changing only the port leaves existing access-control problems in place.
Remediation
Review security groups, subnets, and routing to restrict connections to required clients. Apply database authentication and TLS. If there is a reason to use another port, verify engine support and update application connection settings and allowed traffic together.
Examples
These excerpts compare PostgreSQL ports 5432 and 5433. Configure storage and networking separately; do not adopt the sample password or final-snapshot omission as operational policy.
Before
resource "aws_db_instance" "example" {
engine = "postgres"
instance_class = "db.t3.micro"
username = "foo"
password = "foobarbaz"
skip_final_snapshot = true
port = 5432
}
After
resource "aws_db_instance" "example" {
engine = "postgres"
instance_class = "db.t3.micro"
username = "foo"
password = "foobarbaz"
skip_final_snapshot = true
port = 5433
}
Only the port changes to 5433. This setting alone neither restricts callers nor encrypts traffic.