Quick Search

Threads: 9,437
Posts: 33,517
Members: 3,615
Welcome to our newest member, m6ll7yk2y
Indian Domain Name Blog

TBR Domains

DomainBits Blog

AmazingDomains.co.uk

Domain Name Forum

Buy a Domains Name

Sell Domain Names

Arbel Arif

Domainer from India

Hyderabad

DN Attorney

Australian Domains

Hindi Domain Names

Napier Domains

UK Domain Forum





 
INForum.in - Home of the Indian Domain Name Industry
  #1 (permalink)  
Old 07-01-2010, 03:25 PM
catchnames catchnames is offline
Senior Member
 
Join Date: Apr 2009
Posts: 188
iTrader: (0)
Thanks: 38
Thanked 26 Times in 18 Posts
catchnames is on a distinguished road
Default Beware if you are using Filezilla

I love filezilla, but what happened this month will make me to rethink if I need another ftp program. I am using filezilla 3.1.3.1 client on my PC. Suddenly one good day when I tried to access one of my website,Firefox gave warning as "Reported attack page". When you see this type of issue with your webpage your heartbeat increases.It means youe Web server is hacked!!

I have posted my horror story at

Visible Blog: Filezilla Security Issues - Hackers are exploiting it
Reply With Quote
The Following 2 Users Say Thank You to catchnames For This Useful Post:
Ceres (07-06-2010), Jeff (07-01-2010)
  #2 (permalink)  
Old 07-04-2010, 01:43 PM
abhishekjha abhishekjha is offline
Senior Member
 
Join Date: Nov 2008
Posts: 262
iTrader: (2)
Thanks: 25
Thanked 16 Times in 14 Posts
abhishekjha will become famous soon enoughabhishekjha will become famous soon enough
Default Re: Beware if you are using Filezilla

your computer was infected with trojan 'Gumblar' so it happened, the problem doesn't seem to be coming from filezilla itself as i too happen to download its latest version few days back and everything works superb, if you have trojan problem in windows then first buy Original Windows CD not pirated or copied one and when even that doesnt work, just start using linux instead it wont get affected by viruses and trojans as much as windows pc's.
correct me if im wrong!
__________________
| | . | | Know Me | |
Reply With Quote
The Following User Says Thank You to abhishekjha For This Useful Post:
Jeff (07-04-2010)
  #3 (permalink)  
Old 07-04-2010, 04:12 PM
catchnames catchnames is offline
Senior Member
 
Join Date: Apr 2009
Posts: 188
iTrader: (0)
Thanks: 38
Thanked 26 Times in 18 Posts
catchnames is on a distinguished road
Default Re: Beware if you are using Filezilla

This is wrong to make assumptions without asking first.I am using licensed windows xp with antivirus on it. I do admit that antivirus did fail.But why save password in cleartext.Also, to let you know the server was uploaded files from numerous ip.SO I hope all were infected.Just why not put a gate.
Here are list of IP from where files were uploaded on my server.[see attachment]
Also, windows is installed on 95% of personal computer.SO why open door for hackers on 95% of computer.
Attached Files
File Type: txt ftplog.txt (10.2 KB, 5 views)
Reply With Quote
  #4 (permalink)  
Old 07-06-2010, 03:58 AM
monood monood is offline
Junior Member
 
Join Date: Jun 2009
Posts: 16
iTrader: (0)
Thanks: 1
Thanked 4 Times in 2 Posts
monood is on a distinguished road
Default Re: Beware if you are using Filezilla

I use Filezilla, it's fine to me. I don't save the password on it.
__________________
justhost coupon
Reply With Quote
  #5 (permalink)  
Old 07-06-2010, 04:35 AM
catchnames catchnames is offline
Senior Member
 
Join Date: Apr 2009
Posts: 188
iTrader: (0)
Thanks: 38
Thanked 26 Times in 18 Posts
catchnames is on a distinguished road
Default Re: Beware if you are using Filezilla

Quote:
Originally Posted by monood View Post
I use Filezilla, it's fine to me. I don't save the password on it.
You are safe then.I wish I would have known this issue before,I use to save password in site manager.
Reply With Quote
  #6 (permalink)  
Old 07-24-2010, 09:47 AM
chaudi chaudi is offline
Senior Member
 
Join Date: Sep 2009
Posts: 147
iTrader: (0)
Thanks: 3
Thanked 27 Times in 23 Posts
chaudi is on a distinguished road
Default Re: Beware if you are using Filezilla

Since it's open source it's open season for hackers. I think it is better now, but you right a year or two ago it was spyware.
Reply With Quote
  #7 (permalink)  
Old 11-12-2010, 08:36 AM
mrchris's Avatar
mrchris mrchris is offline
Senior Member
 
Join Date: Sep 2010
Posts: 111
iTrader: (0)
Thanks: 19
Thanked 15 Times in 8 Posts
mrchris is on a distinguished road
Default Re: Beware if you are using Filezilla

LOL's yeah filezilla is a 'old school' lazy way of getting passwords etc
same as wsftp.
for a laugh do a gaagle for
[dir] parent directory index of /backup

for .Net SQL pwd
[dir] parent directory index of /App_Code
[dir] parent directory index of /App_Data

you can also get the web.config files
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Beware on April Fool's Day Ceres The Lounge 4 04-01-2009 04:54 PM
Beware of the beginners mistake. vlada General Indian Domain Name Discussion 12 01-20-2009 03:50 PM
Beware if you get this email tinggg General Indian Domain Name Discussion 5 09-06-2008 08:18 PM


All times are GMT. The time now is 08:32 PM.

 

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.0.0

A vBSkinworks Design

Please Note: INForum reserves the right to remove domains that are listed here that we consider, in our sole discretion, to have no legitimate reason for their registration other than to trade off the goodwill of a third party.