Ensure that Microsoft Azure network security groups (NSGs) do not allow unrestricted access on TCP port 1433 in order to protect against attackers that use brute force methods to gain access to Azure virtual machines associated with these NSGs. TCP port 1433 is used by Microsoft SQL Server, a secure and performant object-relational database system (RDBMS) developed by Microsoft.
Allowing unrestricted access to your Azure virtual machines (VMs) via network security groups (NSGs) can increase opportunities for malicious activities such as hacking, brute-force attacks, and SQL injection attacks.
Audit
To determine if your Azure network security groups allow unrestricted access on TCP ports 1433, perform the following actions:
Remediation / Resolution
To update your Azure NSG rule(s) configuration in order to restrict MSSQL access to trusted entities only, such as admin IP addresses or IP ranges, perform the following actions:
References
- Azure Official Documentation
- Azure network security overview
- Network security groups
- Create, change, or delete a network security group
- Azure best practices for network security
- Azure PowerShell Documentation
- az mysql server
- az network nsg list
- az network nsg rule list
- az network nsg rule update
Unlock the Remediation Steps
Free 30-day Trial
Automatically audit your configurations with Conformity
and gain access to our cloud security platform.
You are auditing:
Check for Unrestricted MSSQL Access
Risk Level: High