Quote:
Originally Posted by freecartoonporn
damn , i am using filezilla, gotta check it out. thanks for the info.
update: now they use base64 encode to store passwords, still sucks. i guess. but who were injecting little php redirect ?
was it filezilla or some other trojan who found the password file ?
|
I see them base64 encoded under AppData\Romaing\recentservers.xml, however you can easily decode them at
https://www.base64decode.org/