{"id":14029,"date":"2026-09-21T08:58:08","date_gmt":"2026-09-21T06:58:08","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=14029"},"modified":"2026-09-21T08:58:13","modified_gmt":"2026-09-21T06:58:13","slug":"audit-privind-expunerea-porturilor-serverului-ssh-rdp-accesul-la-baze-de-date-si-la-panoul-de-control","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/ro\/knowledgebase\/server-port-exposure-audit-ssh-rdp-database-and-control-panel-access\/","title":{"rendered":"Audit privind expunerea porturilor serverului: acces SSH, RDP, la baze de date \u0219i la panoul de control"},"content":{"rendered":"<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">A server port exposure audit checks whether essential services are reachable from the public internet. The goal is to keep only the access that users need, while placing administration and database services behind stronger restrictions such as a VPN, IP allowlisting, or firewall rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Review ports 22, 3389, 3306, 5432, 2083, and 2087 separately. An open port does not always mean that access is possible, but it does show that a service may be reachable and should have an intentional security policy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/server-port-exposure-audit-ssh-rdp-database-and-control-panel-access\/#What_each_port_is_used_for\" >What each port is used for<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/server-port-exposure-audit-ssh-rdp-database-and-control-panel-access\/#What_acceptable_exposure_looks_like\" >What acceptable exposure looks like<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/server-port-exposure-audit-ssh-rdp-database-and-control-panel-access\/#How_to_perform_the_audit\" >How to perform the audit<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/server-port-exposure-audit-ssh-rdp-database-and-control-panel-access\/#Remediation_by_risk_level\" >Remediation by risk level<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/ro\/knowledgebase\/server-port-exposure-audit-ssh-rdp-database-and-control-panel-access\/#When_to_repeat_the_audit\" >When to repeat the audit<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_each_port_is_used_for\"><\/span>What each port is used for<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Port<\/th><th>Service<\/th><th>Default exposure pattern<\/th><\/tr><\/thead><tbody><tr><td>22<\/td><td>SSH<\/td><td>Private or restricted to administration IPs<\/td><\/tr><tr><td>3389<\/td><td>RDP<\/td><td>Private or restricted to administration IPs<\/td><\/tr><tr><td>3306<\/td><td>MySQL or MariaDB database access<\/td><td>Private; public access should be exceptional<\/td><\/tr><tr><td>5432<\/td><td>PostgreSQL database access<\/td><td>Private; public access should be exceptional<\/td><\/tr><tr><td>2083<\/td><td>Secure control panel access<\/td><td>Restricted or protected by an access policy<\/td><\/tr><tr><td>2087<\/td><td>Secure administrative control panel access<\/td><td>Restricted to authorised administrators<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<\/div>\n\n<div id=\"mybox-3160765357\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Acces timpuriu<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Mai ave\u021bi nevoie de ajutor?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contacta\u021bi echipa noastr\u0103 de servicii pentru clien\u021bi.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Trimite mesaj<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">SSH provides direct command-line control over a hosting account and is commonly used for website management, troubleshooting, backups, and server administration. That level of access makes port 22 an administrative entry point, not a general public service. See <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/comenzi-ssh-esentiale-un-ghid-practic-pentru-administrarea-serverelor\/\">mybox&#8217;s SSH command reference<\/a> for the role of SSH in server administration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ports 3306 and 5432 provide access to database services. A database port should normally be reachable only by the application server, an internal network, or approved administration addresses. A website does not need its database port exposed to every internet user.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ports 2083 and 2087 provide secure control panel access. A control panel can manage sensitive settings such as websites, domains, email accounts, databases, SSL certificates, backups, cron jobs, and SSH access. Because the panel can control many parts of a hosting environment, access should be limited to the people and networks that administer it. The <a href=\"https:\/\/mybox.com\/help\/ro\/baza-de-cunostinte\/mybox-panel-vs-cpanel\/\">mybox panel overview<\/a> describes these administrative functions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_acceptable_exposure_looks_like\"><\/span>What acceptable exposure looks like<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>SSH on port 22:<\/strong> Keep it private where possible. If administrators need remote access, allow only approved source IP addresses or require access through a VPN. Use key-based authentication instead of relying only on passwords.<\/li>\n\n\n\n<li><strong>RDP on port 3389:<\/strong> Keep it off the public internet where possible. Place it behind a VPN or allow connections only from fixed administration IP addresses.<\/li>\n\n\n\n<li><strong>Database ports 3306 and 5432:<\/strong> Allow connections only from the application host, internal network, VPN, or specific administration addresses. They should not be open to all internet sources for normal website operation.<\/li>\n\n\n\n<li><strong>Control panel ports 2083 and 2087:<\/strong> Restrict access to authorised users and trusted networks. If public access is required, apply IP allowlisting or another access control layer and use strong authentication.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The correct exposure depends on how the service is used. A public port can be acceptable when it is required for a defined workflow and protected by a narrow source-IP rule. A port that has no business purpose should be closed rather than left available.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_perform_the_audit\"><\/span>How to perform the audit<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>List the server&#8217;s public addresses.<\/strong> Record every public IPv4 or IPv6 address that can receive connections. Include cloud instances, dedicated servers, and other systems used for administration or databases.<\/li>\n\n\n\n<li><strong>Check each target port from outside the server.<\/strong> Test 22, 3389, 3306, 5432, 2083, and 2087 from a network that is not the server&#8217;s internal network. Record whether each port appears open, closed, or filtered.<\/li>\n\n\n\n<li><strong>Identify the service behind an open port.<\/strong> Confirm that an open port belongs to the expected service. A port that is open without a known purpose requires review before it is kept accessible.<\/li>\n\n\n\n<li><strong>Compare access with the intended users.<\/strong> For each open port, write down who needs access, from which network, and for what task. Administration ports should not be available to every internet address unless there is a clear operational reason.<\/li>\n\n\n\n<li><strong>Review the firewall rule.<\/strong> Check whether the rule allows all sources or only approved addresses. Replace broad rules with source-specific rules where the service does not need public reachability.<\/li>\n\n\n\n<li><strong>Choose the restriction.<\/strong> Close unused ports. For required administration access, use a VPN or IP allowlisting. For database access, allow only the application server or approved private networks.<\/li>\n\n\n\n<li><strong>Harden SSH access.<\/strong> Use key-based authentication, remove access that is no longer needed, and keep SSH reachable only from the administration path where practical.<\/li>\n\n\n\n<li><strong>Test after every change.<\/strong> Verify that approved administrators can still connect and that an unauthorised network can no longer reach the restricted port.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Remediation_by_risk_level\"><\/span>Remediation by risk level<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Close the port<\/strong> when the service is unused or when administration can be performed through another approved path. Removing an unnecessary exposure reduces the number of services that must be protected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Use a VPN<\/strong> when several administrators or systems need access without placing the service directly on the public internet. The VPN becomes the controlled entry point, while SSH, RDP, database, or panel access remains private.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Use IP allowlisting<\/strong> when administrators connect from fixed office, home, or management-network addresses. Permit only those addresses and review the list when an administrator&#8217;s network changes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Use firewall rules<\/strong> to define which source addresses may reach each port. A separate rule for SSH, RDP, each database service, and each control panel port makes the audit easier to review and reduces accidental broad access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"When_to_repeat_the_audit\"><\/span>When to repeat the audit<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Repeat the audit after a firewall change, server migration, new remote-access requirement, or control panel change. Also review the port list when an application begins using a database from another host. The expected result is a short list of open ports with a named purpose, an approved source, and a clear owner.<\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[10],"manual_kb_tag":[],"class_list":["post-14029","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-safety"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/14029","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/14029\/revisions"}],"predecessor-version":[{"id":14030,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb\/14029\/revisions\/14030"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/media?parent=14029"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manualknowledgebasecat?post=14029"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/ro\/wp-json\/wp\/v2\/manual_kb_tag?post=14029"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}