Opened 11 years ago
Closed 8 years ago
#8237 closed Bug report (duplicate)
|Reported by:||ftpuserd||Owned by:|
|Keywords:||password encrypt security||Cc:||yerenkov.scott@…|
|Component version:||Operating system type:||Windows|
|Operating system version:||All|
Just found out about this due to a recurrent series of website hacks which seem on investigation to be to this error.
It's really lax. Even if FZ is not being used at the time, any virus or malware can scoop up the ftp addresses, usernames and passwords.
I have been recommending FZ for years, but I am now putting out an advisory to stop using it as a matter of urgency. For those using it to manage a lot of sites, a single infection on a client machine could trigger weeks of server clean-up work.
And I'm frankly shocked by the developer's response to tickets and forum posts on this over the years. It borders on negligence for such an otherwise excellent tool.
Change History (3)
comment:1 by , 11 years ago
|Status:||new → closed|
comment:2 by , 8 years ago
|Status:||closed → reopened|
This is definitely a major weakness in the software, and the issue is not resolved if I am able to go into "%appdata%\FileZilla\sitemanager.xml" and get this sort of information (I typed in some random information into the Site Manager in the GUI of FileZilla and this file was generated with all of the information completely in plain text):
<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
I am sure that there is a very simple solution to this, such as encrypting it and then storing the encryption key (protected by the user's username and password) on the site in their account. Or to offer the ability at least to pay for some space to store keys on the site. And even if storing on the site would be a bad idea, at least offering encryption and then giving an encryption key to maybe be stored on a USB stick or something.
comment:3 by , 8 years ago
|Status:||reopened → closed|
This is a duplicate of either ticket:5530 or ticket:8173, depending on the facility used for encryption.
Hey son! If it would be a security issue, you should be able do decrypt the password below.