Tools

Configure Serv-U to protect against brute force attacks

This article provides ways to block unauthorized users to login and how to enable the anti-hammering feature of Serv-U

First published date

11/29/2018 10:40 PM

Last published date

3/14/2025 9:16 PM

Overview

A brute force attack is an attempt by a hacker to gain illegitimate access to your system by attempting to login using random usernames in rapid succession. This helps admins to configure Serv-U to block users who keep on logging in using incorrect credentials.

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Resolution

  1. Regularly audit your user list to ensure that all users have been given proper permissions.
  2. Go to Limits & Settings > Limits > Passwords > Require complex passwords.
  3. Enable minimum password length requirements under Go to Limits & Settings > Limits > Passwords > Minimum password length
  4. Enable minimum password length requirements.
    Note: Six characters or more is considered more secure.
  5. Go to Limits & Settings > Limits > Passwords > Automatically expire password to reduce the likelihood of a compromised password being used for an extended period of time.
  6. Go to Server Limits & Settings > Settings and enable anti-hammering.



Blocked IP address will show in the IP access tab.

 

Adding Exceptions 

  • Go to Server Details > IP Access menu. In some cases, automated FTP processes or procedures may accidentally trigger this anti-hammering feature, preventing critical processes from running. Serv-U 9.0 and above. Counteract this by not automatically blocking users who are allowed in the Serv-U IP Access list. Follow these steps to specify a host who should always be able to connect:
  • Go to Global > Server Details > IP Access tab or Domains > Domain Details > IP Access tab
  • Put the Denied, Allowed and wildcard entry in this specific order ** very important.
    • Denied IPs at the top
    • Allowed or IP at the middle (allowed all the time)
    • *.*.*.* wildcard at the very bottom


       
  • Also take note that, whenever you manually add an allowed or denied IP address, the new entry will be at the bottom of the list. 
  • You need to make sure that the wildcard entry *.*.*.* is always at the bottom of the list.