Thoughts on the sitemanager.xml file

Come here to discuss FileZilla and FTP in general

Moderator: Project members

Post Reply
Message
Author
TimBrowning
500 Command not understood
Posts: 2
Joined: 2013-08-20 14:02
First name: Tim
Last name: Browning

Thoughts on the sitemanager.xml file

#1 Post by TimBrowning » 2013-08-20 14:10

Like loads of other people, I fell foul of the trojan that steals the sitemanager.xml file. And all my sites were 'hacked'. My laptop is 'secured' by NOD32 and MalwareBytes - both of which are fully up-to-date paid versions, so I don't need a lecture on security.

I have now taken steps to try and make sure the theft of the xml files doesn't happen again. In doing so, I struck me that if these files were user-defined, ie not called the default filenames and stored in a user-definable place, then the kiddy-scripts used to thieve teh files will have a much harder time.

Forgive me if this has been discussed before, but it seems to me that FileZilla is more likely to keep it's user-base if simple steps like these are taken to put us more at ease over security issues.

Anyone have anything to add?

ftanner
503 Bad sequence of commands
Posts: 20
Joined: 2013-08-07 16:17
First name: Frank
Last name: Tanner

Re: Thoughts on the sitemanager.xml file

#2 Post by ftanner » 2013-08-20 22:25

TimBrowning wrote:Like loads of other people, I fell foul of the trojan that steals the sitemanager.xml file. And all my sites were 'hacked'. My laptop is 'secured' by NOD32 and MalwareBytes - both of which are fully up-to-date paid versions, so I don't need a lecture on security.

I have now taken steps to try and make sure the theft of the xml files doesn't happen again. In doing so, I struck me that if these files were user-defined, ie not called the default filenames and stored in a user-definable place, then the kiddy-scripts used to thieve teh files will have a much harder time.

Forgive me if this has been discussed before, but it seems to me that FileZilla is more likely to keep it's user-base if simple steps like these are taken to put us more at ease over security issues.

Anyone have anything to add?
It would also help if they encrypted the file too, but they refuse to do that.

User avatar
botg
Site Admin
Posts: 35562
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

Re: Thoughts on the sitemanager.xml file

#3 Post by botg » 2013-08-21 06:34

You can disable saving of passwords in the settings dialog of FileZilla.

qholmes
500 Command not understood
Posts: 2
Joined: 2013-08-26 14:59
First name: Quentin
Last name: Holmes

Re: Thoughts on the sitemanager.xml file

#4 Post by qholmes » 2013-08-26 15:22

I dont think that was the point of this post. I believe they are looking for another better option for security so that they can safely use a feature they like... I am currently researching this exact thing right now.

Q

TimBrowning
500 Command not understood
Posts: 2
Joined: 2013-08-20 14:02
First name: Tim
Last name: Browning

Re: Thoughts on the sitemanager.xml file

#5 Post by TimBrowning » 2013-08-28 15:23

Issue neatly avoided there, once again. Listening to users is obviously to be steadfastly ignored.

User avatar
boco
Contributor
Posts: 26935
Joined: 2006-05-01 03:28
Location: Germany

Re: Thoughts on the sitemanager.xml file

#6 Post by boco » 2013-08-28 17:24

Nope, there simply are no plans for any type of ''encryption'' or obfuscation.
No support requests over PM! You will NOT get any reply!!!
FTP connection problems? Please read Network Configuration.
FileZilla connection test: https://filezilla-project.org/conntest.php
FileZilla Pro support: https://customerforum.fileZilla-project.org

Post Reply