GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Recommendations for secure ftp software? (https://gfy.com/showthread.php?t=1029634)

Shoplifter 07-09-2011 01:02 PM

Recommendations for secure ftp software?
 
It looks like someone may have been into my cuteftp.

Anyone recommend a secure ftp program that stores passwords in an encypted format?

CYF 07-09-2011 01:08 PM

use sftp. Don't store passwords.

Klen 07-09-2011 01:19 PM

Step number one:use SFTP protocol only and restrict access to your ip or your key only.Step number two:use winscp or filezilla portable version

MediaGuy 07-09-2011 02:13 PM

Most ftp clients use an xml file that can be jacked when you upload - you can use sftp, or change your password everytime or just never save your password in the site manager.

.

Captain Kawaii 07-09-2011 02:16 PM

What they said... Cool advice guys.

Cash4Me 07-09-2011 02:50 PM

You should care about your network not about the FTP client.
Even if the app stores password with encryption, FTP protocol send username and password in plain text, anyone on your network who is sniffing (Wireshark?) your data can read that.
Use SSH with SFTP, I advice you to use WinSCP client if your hosting has SSH enabled

MediaGuy 07-09-2011 02:57 PM

Quote:

Originally Posted by Cash4Me (Post 18271345)
You should care about your network not about the FTP client.
Even if the app stores password with encryption, FTP protocol send username and password in plain text, anyone on your network who is sniffing (Wireshark?) your data can read that.
Use SSH with SFTP, I advice you to use WinSCP client if your hosting has SSH enabled

Are they just reading from the file the user/pass are "sent" from or from the actual data transfer between the client and the FTP server?

I had that problem once and just stopped saving - never had another hack again. No data file, no data find...

I thought?

CYF 07-09-2011 03:12 PM

Quote:

Originally Posted by MediaGuy (Post 18271354)
Are they just reading from the file the user/pass are "sent" from or from the actual data transfer between the client and the FTP server?

I had that problem once and just stopped saving - never had another hack again. No data file, no data find...

I thought?

regular ftp sends your password over the internet in the clear. Anyone between you and your server can read it. FTP is just fine if you're running a public repository that people can download from where passwords are not sent. If you're using FTP for anything that requires a password then FTP is outdated for that use.

SFTP or SCP is the way to go for secure transfers.

Cash4Me 07-10-2011 04:29 AM

Quote:

Originally Posted by MediaGuy (Post 18271354)
Are they just reading from the file the user/pass are "sent" from or from the actual data transfer between the client and the FTP server?

I had that problem once and just stopped saving - never had another hack again. No data file, no data find...

I thought?

Packets between your client and the FTP server.

Dappz 07-10-2011 04:33 AM

it insteresting to know more ftp client to be use :)


All times are GMT -7. The time now is 11:20 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc