INForum.in - Home of the Indian Domain Industry
Results 1 to 7 of 7
  1. #1
    catchnames is offline Senior Member
    Join Date
    Apr 2009
    Posts
    222
    Thanks
    48
    Thanked 37 Times in 21 Posts

    Default Beware if you are using Filezilla

    I love filezilla, but what happened this month will make me to rethink if I need another ftp program. I am using filezilla 3.1.3.1 client on my PC. Suddenly one good day when I tried to access one of my website,Firefox gave warning as "Reported attack page". When you see this type of issue with your webpage your heartbeat increases.It means youe Web server is hacked!!

    I have posted my horror story at

    Visible Blog: Filezilla Security Issues - Hackers are exploiting it

  2. The Following 2 Users Say Thank You to catchnames For This Useful Post:

    Ceres (07-06-2010),Jeff (07-01-2010)

  3. #2
    abhishekjha is offline Senior Member
    Join Date
    Nov 2008
    Posts
    262
    Thanks
    25
    Thanked 17 Times in 15 Posts

    Default Re: Beware if you are using Filezilla

    your computer was infected with trojan 'Gumblar' so it happened, the problem doesn't seem to be coming from filezilla itself as i too happen to download its latest version few days back and everything works superb, if you have trojan problem in windows then first buy Original Windows CD not pirated or copied one and when even that doesnt work, just start using linux instead it wont get affected by viruses and trojans as much as windows pc's.
    correct me if im wrong!
    | | . | | Know Me | |

  4. The Following User Says Thank You to abhishekjha For This Useful Post:

    Jeff (07-04-2010)

  5. #3
    catchnames is offline Senior Member
    Join Date
    Apr 2009
    Posts
    222
    Thanks
    48
    Thanked 37 Times in 21 Posts

    Default Re: Beware if you are using Filezilla

    This is wrong to make assumptions without asking first.I am using licensed windows xp with antivirus on it. I do admit that antivirus did fail.But why save password in cleartext.Also, to let you know the server was uploaded files from numerous ip.SO I hope all were infected.Just why not put a gate.
    Here are list of IP from where files were uploaded on my server.[see attachment]
    Also, windows is installed on 95% of personal computer.SO why open door for hackers on 95% of computer.
    Attached Files Attached Files

  6. #4
    monood is offline Junior Member
    Join Date
    Jun 2009
    Posts
    16
    Thanks
    1
    Thanked 4 Times in 2 Posts

    Default Re: Beware if you are using Filezilla

    I use Filezilla, it's fine to me. I don't save the password on it.

  7. #5
    catchnames is offline Senior Member
    Join Date
    Apr 2009
    Posts
    222
    Thanks
    48
    Thanked 37 Times in 21 Posts

    Default Re: Beware if you are using Filezilla

    Quote Originally Posted by monood View Post
    I use Filezilla, it's fine to me. I don't save the password on it.
    You are safe then.I wish I would have known this issue before,I use to save password in site manager.

  8. #6
    chaudi is offline Senior Member
    Join Date
    Sep 2009
    Posts
    152
    Thanks
    3
    Thanked 27 Times in 23 Posts

    Default Re: Beware if you are using Filezilla

    Since it's open source it's open season for hackers. I think it is better now, but you right a year or two ago it was spyware.

  9. #7
    mrchris's Avatar
    mrchris is offline Senior Member
    Join Date
    Sep 2010
    Posts
    111
    Thanks
    19
    Thanked 16 Times in 9 Posts

    Default Re: Beware if you are using Filezilla

    LOL's yeah filezilla is a 'old school' lazy way of getting passwords etc
    same as wsftp.
    for a laugh do a gaagle for
    [dir] parent directory index of /backup

    for .Net SQL pwd
    [dir] parent directory index of /App_Code
    [dir] parent directory index of /App_Data

    you can also get the web.config files

 

 

Similar Threads

  1. Beware on April Fool's Day
    By Ceres in forum The Lounge
    Replies: 4
    Last Post: 04-01-2009, 04:54 PM
  2. Beware of the beginners mistake.
    By vlada in forum General Indian Domain Name Discussion
    Replies: 12
    Last Post: 01-20-2009, 02:50 PM
  3. Beware if you get this email
    By tinggg in forum General Indian Domain Name Discussion
    Replies: 5
    Last Post: 09-06-2008, 08:18 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •