Search found 128 matches

by xeon
2012-04-28 09:33
Forum: FileZilla Client Support
Topic: new errors with vsftpd 3.0.0
Replies: 2
Views: 3278

new errors with vsftpd 3.0.0

Hello, I've been testing out the new version of vsftpd 3.0.0 and there appear to be some new errors when vsftpd's idle timeout occurs. 04:57:39 Response: 421 Timeout. 04:57:39 Trace: Unexpected reply, no reply was pending. 04:57:39 Trace: CTlsSocket::Failure(-9, 0) 04:57:39 Error: GnuTLS error -9: A...
by xeon
2012-04-22 23:34
Forum: FileZilla Client Support
Topic: Filezilla password plaintext disaster
Replies: 6
Views: 6276

Re: Filezilla password plaintext disaster

BigBang wrote:They pay me for security and support.
BigBang wrote:I got a Trojan on my system
Are you sure you're in the right line of work? :roll:
by xeon
2012-04-20 02:38
Forum: FileZilla Client Support
Topic: GnuTLS question
Replies: 1
Views: 841

GnuTLS question

Hello,

Are there any plans to build the windows version of filezilla with a newer GnuTLS?

I'm mostly interested in AES-GCM which are TLS 1.2 ciphers supported in newer versions of GnuTLS.

I *think* the support for them starts at version 3.0.0 but I could be wrong.

Thanks
by xeon
2012-04-18 21:21
Forum: FileZilla Client Support
Topic: TLS version with ftpes
Replies: 3
Views: 1718

Re: TLS version with ftpes

Yes, FileZilla also supports TLS 1.2 Great, is there a way to check what it's using for a particular session? I'm surprised there's no mention of it in the session details, where it displays the cipher and other information. Edit: I found it in the handshake while using wireshark, but I still think...
by xeon
2012-04-18 13:10
Forum: FileZilla Client Support
Topic: TLS version with ftpes
Replies: 3
Views: 1718

TLS version with ftpes

Hello,

Is there a way to find out which tls version is being used when connected to an ftpes server via filezilla client?

The server supports up to TLS 1.2 so I assume the client will use that?

It'd be nice to confirm.
by xeon
2012-04-11 05:52
Forum: FileZilla Client Support
Topic: FTPES session reuse
Replies: 1
Views: 1415

FTPES session reuse

Hello, I noticed in vsftpd's newest 3.0.0 release the changelog states there's a problem with filezilla when it comes to FTPES compatibility. "Unfortunately the default vsftpd SSL confiuration still doesn't fully work with FileZilla, because FileZilla has a data connection security problem: no ...
by xeon
2012-02-10 16:39
Forum: FileZilla Client Support
Topic: GnuTLS error -12 when trying to connect to with Explicit TLS
Replies: 56
Views: 71282

Re: GnuTLS error -12 when trying to connect to with Explicit

I don't see how saving cpu cycles is silly. People who say this don't seem to understand just how much is wasted by using a cipher like 3DES. If anything needs to be done it's vsftpd's dev needing to change their default cipher to something more efficient such as AES/RC4 or perhaps even multiple ci...
by xeon
2012-02-10 03:37
Forum: FileZilla Client Support
Topic: Econnaborted on PureFTPd
Replies: 6
Views: 2860

Re: Econnaborted on PureFTPd

pureftpd has always been broken in various ways even with the newest version.

Not that it should matter when deciding as vsftpd is far superior to it and proftpd.
by xeon
2012-02-09 19:39
Forum: FileZilla Client Support
Topic: GnuTLS error -12 when trying to connect to with Explicit TLS
Replies: 56
Views: 71282

Re: GnuTLS error -12 when trying to connect to with Explicit

While I disagree that DES-CBC3-SHA is a "weak" cipher I agree with botg's end decision to remove support for it. This is mostly for performance reasons 3DES is one of the slowest ciphers around and does nothing but waste cpu cycles compared to superior alternatives. My preference is alway...
by xeon
2012-01-30 19:27
Forum: General Discussion
Topic: uploading problem
Replies: 1
Views: 2359

Re: uploading problem

Sounds like they want you to use ftpes instead of plain ftp.

Change the encryption setting in your site manager to "Require explicit FTP over TLS".

If you're using the quickconnect bar just prefix the hostname with ftpes://
by xeon
2012-01-29 22:15
Forum: FileZilla Client Support
Topic: GnuTLS error -12 when trying to connect to with Explicit TLS
Replies: 56
Views: 71282

Re: GnuTLS error -12 when trying to connect to with Explicit

While I disagree that DES-CBC3-SHA is a "weak" cipher I agree with botg's end decision to remove support for it. This is mostly for performance reasons 3DES is one of the slowest ciphers around and does nothing but waste cpu cycles compared to superior alternatives. My preference is always...
by xeon
2012-01-25 18:23
Forum: FileZilla Client Support
Topic: File Zilla - Windows 7 - 421 Connections Error
Replies: 10
Views: 4374

Re: File Zilla - Windows 7 - 421 Connections Error

I am at a point here where my patience has almost ran out. I receive the 421 Too many connections open (8) message when uploading files to my server. For the benefit of the Admins on this forum, i am a technically minded person, have read your wiki topics to fix my "broken server". I have...
by xeon
2011-10-28 16:53
Forum: FileZilla Client Support
Topic: Can no longer connect with explicit FTP/TLS
Replies: 6
Views: 5904

Re: Can no longer connect with explicit FTP/TLS

Addendum: Well, I'm still trying to figure out, what it is about my VZW connection (see above) that causes FTP/TLS to fail as noted. I've noticed, that plain, unencrypted FTP works fine, however the TLS equivalent fails. As I'm understanding things right now, both of these work over the same port -...
by xeon
2011-10-10 18:58
Forum: FileZilla Client Support
Topic: 保存在软件中的密码可以被词典的屏幕取词功能获取到
Replies: 4
Views: 5177

Re: 保存在软件中的密码可以被词典的屏幕取词功能获取到

FileZilla client stores passwords in plaintext anyway so I don't see how this is significant at all.
by xeon
2011-05-03 00:35
Forum: General Discussion
Topic: Using sftp
Replies: 12
Views: 4238

Re: Using sftp

Hmm, shared hosting, guess why I am not using it. Hosting providers rarely maintain their systems to update to the most recent software versions and thus potentially miss vital security fixes. Their rationale: "Can't update, it breaks our customer's websites". In a way, it's like IE6 in a...