Tools

Configure anti-hammering of Serv-U to block unauthorized users

An article showing steps on how to configure the anti-hammering feature of Serv-U.

First published date

9/5/2019 5:58 PM

Last published date

6/19/2025 1:35 PM

Overview

Enabling this option prevents brute-force passwords from using some dictionary-style attacks to locate a valid password for a user account. Using strong, complex passwords defeats most dictionary attacks. However, enabling this option ensures Serv-U does not waste time processing connections from these illegitimate sources.

When configuring this option, ensure there is some room for legitimate users to correct an incorrect password attempt before they are blocked.

When enabled, this option temporarily blocks IP addresses that fail to successfully login after the specified number of attempts within the specified number of seconds for the specified number of minutes. IP addresses blocked in this way can be viewed on the appropriate IP Access tab. A successful login resets the counter that is tracking login attempts.

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Resolution

  1. Open Serv-U Management console.
  2. Go to the Global and/or Domain level.
  3. Select Limits and Settings.
  4. Go to the Settings tab.
  5. Check the box “Block users who connect more than X times within X seconds for X minutes (0 for permanently).
  1. Click Save.