warning filezillaserver full of trojans

Have the feeling that everybody is staring at you in the other forums? Then look here, in this forum nobody does care what you say ;-)

Moderator: Project members

Post Reply
Message
Author
brouhon
500 Command not understood
Posts: 1
Joined: 2005-03-28 11:21

warning filezillaserver full of trojans

#1 Post by brouhon » 2005-03-28 11:28

monday march 28 2005
started fizillaserver for the first time on my localhost
as long as it runs norton antivirus 2005 keeps trowing
intrusion alert windows with trojans
path c:\apachefriends\filezilla\filezillaserver.exe

ive got the filezilla as part of xammp for windows
donloaded at apachefriends.org :(

see u dudes

User avatar
botg
Site Admin
Posts: 35558
Joined: 2004-02-23 20:49
First name: Tim
Last name: Kosse

#2 Post by botg » 2005-03-28 11:47

Most likely a false alarm. Norton software is extremely unreliable imo.

The official releases of FileZilla (Server) as listed on http://sourceforge.net/projects/filezilla do not contain any malicious software.

chibijon
500 Command not understood
Posts: 5
Joined: 2005-04-17 10:21

#3 Post by chibijon » 2005-04-17 10:33

I, too am concerned about FileZilla acting suspicious. My firewall is catching Filezilla attempting to connect to filezilla.sourceforge.org port 80 periodically (once every few hours). I have it set to use a fixed IP, NOT attempt to determine external IP address, so there should be no reason why FileZilla is doing ANYTHING but listen on port 21 and the admin port unless somebody connects. What is it trying to do and how do I stop it?

mitch
426 Connection timed out
Posts: 52
Joined: 2004-09-11 00:43

#4 Post by mitch » 2005-04-17 21:51

i am not an expert but
1. where did you download it from?
2. what version?

3. the server or the client?

4. what A/V, anti spyware,trogen hunter programs do you have/use?

i have been using it for about a year through several upgrades and have never had it go out to "call home" ( using sygate firewall)

i saw that one of the junk P2P's was using filezilla with their junk !

i will state that there are no trogens/virus or anything in Filezilla!

just a good working reliable FTP program

chibijon
500 Command not understood
Posts: 5
Joined: 2005-04-17 10:21

#5 Post by chibijon » 2005-04-17 23:23

I am seeing this unusual activity both with version 0.9.4e from apachefriends.org (as part of XAMPP) and with version 0.9.6a from Filezilla itself. Sygate Personal Firewall is what's catching it.

Perry
500 Syntax error
Posts: 16
Joined: 2005-04-28 19:57

#6 Post by Perry » 2005-04-30 01:08

If you compiled the filezilla yourself, then it should be clean (or else, you have bad problems -- local virus infected your compiled files!)

If you got it from someone else, you might ask the original compiler for a signature -- such as an md5 hash -- and check that your version is unaltered from their version.

Patte
450 Internal Error
Posts: 36
Joined: 2004-03-03 15:32

#7 Post by Patte » 2005-05-02 22:32

could be the compiler itself.
get a clean compiler, review the fz source, compile, ready.

Post Reply