Jump to content

FileZilla the Trojan and a security Nightmare


Recommended Posts

Just figured I would let you know that there have been issues lately with Filezilla,

 

IF your computer picks up a trojan, then there can be issues with the way filezilla stores saved passwords..

these are stored in a plain text xml file and can be read easily,

 

we have seen an influx of users sites being "Hacked" only to discover that the hackers are using the account owners own username and password....

 

after alot of research we found the common thread was Filezilla,

others have reached the same conclusion.... and this has been talked about on the filezilla board.

 

 

the developer has refused to do anything about it, his attitude is SO....

 

 

I would suggest that IF you use file zilla that you

1 DONT store passwords,

 

also I would suggest booting your pc into secure mode and running the virus scan, see if you find anything weird,

Link to comment
Share on other sites

the developer has refused to do anything about it, his attitude is SO....

 

Why should he? It's not like you're paying him.

 

If you insist on using free software, don't expect the same level of support you would get from paying for something.

Link to comment
Share on other sites

why should he,

Simple answer....

 

RESPONSIBILITY.

 

Nuff said,

 

this was just an informative post,

It dosnt affect me since I wont use that crap, but it has affected a few of our clients....

 

and will affect a few of your clients as well.

 

Once again this is just a public service announcement

Link to comment
Share on other sites

I agree with Merlin. The choice to provide something free is a personal one. Responsibility applies whether paid for or otherwise if you want respect.

 

How would you like it if I offered you a free taxi but never told you that I would run out of petrol in the middle of a riot in Harlem and just said, "Well, what do you expect for free?", as the Taxi got torched and you got shot?

 

The fact is, the open source community is highly respectable and valued globally and people who don't act professionally give it a bad name that it just doesn't deserve. It is counter to the interests of the entire OS community for one major practitioner, such as Filezilla, to take the attitude that, because what they do is free, any old crap will do, especially in relation to security.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated