Tools
Configure Serv-U to protect against brute force attacks
This article provides ways to block unauthorized users to login and how to enable the anti-hammering feature of Serv-U
First published date
Last published date
Overview
Product section
Resolution
- Regularly audit your user list to ensure that all users have been given proper permissions.
- Go to Limits & Settings > Limits > Passwords > Require complex passwords.
- Enable minimum password length requirements under Go to Limits & Settings > Limits > Passwords > Minimum password length
- Enable minimum password length requirements.
Note: Six characters or more is considered more secure. - Go to Limits & Settings > Limits > Passwords > Automatically expire password to reduce the likelihood of a compromised password being used for an extended period of time.
- Go to Server Limits & Settings > Settings and enable anti-hammering.
Blocked IP address will show in the IP access tab.
Adding Exceptions
- Go to Server Details > IP Access menu. In some cases, automated FTP processes or procedures may accidentally trigger this anti-hammering feature, preventing critical processes from running. Serv-U 9.0 and above. Counteract this by not automatically blocking users who are allowed in the Serv-U IP Access list. Follow these steps to specify a host who should always be able to connect:
- Go to Global > Server Details > IP Access tab or Domains > Domain Details > IP Access tab
- Put the Denied, Allowed and wildcard entry in this specific order ** very important.
- Denied IPs at the top
- Allowed or IP at the middle (allowed all the time)
- *.*.*.* wildcard at the very bottom
- Also take note that, whenever you manually add an allowed or denied IP address, the new entry will be at the bottom of the list.
- You need to make sure that the wildcard entry *.*.*.* is always at the bottom of the list.