Insecure Server

Come here to discuss FileZilla and FTP in general

Moderator: Project members

Post Reply
Message
Author
pastor
500 Command not understood
Posts: 3
Joined: 2023-11-16 00:53
First name: Calvin
Last name: Sharpe

Insecure Server

#1 Post by pastor » 2023-11-16 02:57

Hi, could you please help me to configure XAMPP or FileZilla so that when I try to connect the two, FileZilla does not give me this popup: https://www.dropbox.com/scl/fi/liu4eyt7 ... rgacp&dl=0

The popup say: This server does not support FTP over TLS.

If you continue, your password and files will be sent in clear over the internet.


FileZilla:
Status: Insecure server, it does not support FTP over TLS.


Thanks for your help!

User avatar
boco
Contributor
Posts: 26940
Joined: 2006-05-01 03:28
Location: Germany

Re: Insecure Server

#2 Post by boco » 2023-11-16 04:20

If everything I've read is correct, that is impossible.

- According to the XAMPP download page, it includes FileZilla FTP Server 0.9.41 (from February 2012, nearly 12 years old, nevermind).
- FZ Server 0.9.41 does not support FTP over TLS 1.2, the support for it came after that version (in 0.9.43).
- FileZilla Client requires FTP over TLS 1.2 with high grade ciphers, as a minimum.
- They will therefore never be able to communicate with each other, using FTP over TLS.
- FZ Server 0.9.41 is insecure as f*ck and contains numerous known and hell-knows-how-many unknown security vulnerabilities, due to reliance on a very outdated OpenSSL release.

Two options for you:
1. If you are using the server locally, you don't need ANY FTP. Just copy the files to and from the server roots, using Explorer.
2. If you absolutely need FTP, dump the included FTP server and install FileZilla Server 1.7.3 from the FileZilla download page. Support is only done for this version.
No support requests over PM! You will NOT get any reply!!!
FTP connection problems? Please read Network Configuration.
FileZilla connection test: https://filezilla-project.org/conntest.php
FileZilla Pro support: https://customerforum.fileZilla-project.org

Post Reply