Urgent.News

What's breaking now, across thousands of outlets.

Tech

5432 and 1433: two database ports, ten million answers, and the question of what answered

5432 and 1433: two database ports, ten million answers, and the question of what answered The counts Database ports appear at very large scale in internet-wide scans. ZoomEye queries run on 26 September 2026 returned 4,685,422 results for port="5432" , the conventional PostgreSQL port, and 5,877,157 for port="1433" , the conventional Microsoft SQL Server port. Together the two figures exceed ten…

The database ports 5432 and 1433 are frequently scanned across the internet, with scans conducted on September 26, 2026 revealing over ten million hits for each. However, these numbers do not necessarily indicate a large number of exposed databases.

Port-level matches only confirm that a host accepted a connection on that TCP port, without revealing the identity of the service, whether a protocol exchange occurred, or if the host even runs a database. Additionally, ports 5432 and 1433 are common choices, not reserved, allowing for unrelated services or proxies to bind these ports.

Furthermore, a listening socket could potentially be a forwarder, such as a load balancer or cloud provider's managed endpoint, or a security appliance terminating connections. This could inflate the scan results, as these services would appear as individual answers in the scan, even if they are not databases themselves.

Another source of inflation is cloud and hosting ranges, which often include hosts that answer on a port as part of a shared network appliance or managed platform edge. These hosts may not be databases but are included in the scan results nonetheless.

In conclusion, while the ports 5432 and 1433 receive a large amount of inbound connection traffic, this does not definitively indicate the number of exposed databases. Instead, these ports serve as indicators of inbound reachability, and the actual database exposure requires verification from an internal perspective. Regularly scanning these ports and comparing the results with internal inventory can help identify any public endpoints that were unintentionally created.

ZoomEye's platform provides both port-level and fingerprint-level views, making it easier to compare external scans with an organization's internal inventory.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Wednesday 30 September →