Page 1 of 1

Custom Welcome Message

Posted: 2021-10-06 00:59
by bubblesnout
I've just downloaded and installed the latest FileZilla Server and to conform to our security standards I need to adjust the FTP welcome message so it doesn't include the software name or version information. I can see info online that this should be possible but I'm not seeing the option in the Administration interface. Am I missing something or has this option been removed?

Re: Custom Welcome Message

Posted: 2021-10-06 04:53
by oibaf
I confirm that custom messages aren't currently implemented. More of a forgotten thing than an intentional measure. Will probably make a comeback in one of the next releases.

Re: Custom Welcome Message

Posted: 2021-10-06 10:39
by botg
It's trivially easy to identify the used server product and version based on behavior alone. Hiding it is just a failed attempt at security by obscurity.

Re: Custom Welcome Message

Posted: 2021-10-24 20:42
by mincer22
botg wrote:
2021-10-06 10:39
It's trivially easy to identify the used server product and version based on behavior alone. Hiding it is just a failed attempt at security by obscurity.
That's the old way of thinking.
Security by obscurity is rightly dismissed as a LONE security measure. But nowadays obscurity is recommended as an EXTRA, INDEPENDENT security measure.
Failing to include the possibility to hide this information was a bad call.