<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Beware: FileZilla Doesn&#8217;t Protect Your Passwords</title>
	<atom:link href="http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/</link>
	<description>Website insecurity by example</description>
	<lastBuildDate>Sun, 05 Feb 2012 10:06:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Denis</title>
		<link>http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/comment-page-1/#comment-14814</link>
		<dc:creator>Denis</dc:creator>
		<pubDate>Wed, 25 Jan 2012 22:51:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=277#comment-14814</guid>
		<description>In my experience, passwords saved in FileZilla helped hack tens of thousand websites (probably even more) 

Hackers don&#039;t have to steal your desktop. It&#039;s enough to run a trojan on your computer. One minute is enough to scan your computer for known places where programs store passwords and other sensitive information and send that information to hackers. http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/</description>
		<content:encoded><![CDATA[<p>In my experience, passwords saved in FileZilla helped hack tens of thousand websites (probably even more) </p>
<p>Hackers don&#8217;t have to steal your desktop. It&#8217;s enough to run a trojan on your computer. One minute is enough to scan your computer for known places where programs store passwords and other sensitive information and send that information to hackers. <a href="http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/" rel="nofollow">http://blog.unmaskparasites.com/2009/09/23/10-ftp-clients-malware-steals-credentials-from/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/comment-page-1/#comment-14750</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Sat, 21 Jan 2012 05:00:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=277#comment-14750</guid>
		<description>Well this was a little disconcerting to read. I&#039;m going to get Filezilla Portable - thanks Arthur!</description>
		<content:encoded><![CDATA[<p>Well this was a little disconcerting to read. I&#8217;m going to get Filezilla Portable &#8211; thanks Arthur!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh</title>
		<link>http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/comment-page-1/#comment-14655</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Thu, 12 Jan 2012 16:11:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=277#comment-14655</guid>
		<description>I think this post would be more accurate if it were called, &quot;Beware: 90% of the Programs You Use Don’t Protect Your Passwords&quot;.

The intro to the post makes it sound like all these sites are getting hacked because of Filezilla, but most of the hackings have nothing to do with Filezilla. It usually happens because of outdated content management software running on remote servers.

Filezilla is a great program, and there is nothing wrong with what it does. The only danger with the XML file is if someone steals your laptop. That is why laptop hard drives should be encrypted...</description>
		<content:encoded><![CDATA[<p>I think this post would be more accurate if it were called, &#8220;Beware: 90% of the Programs You Use Don’t Protect Your Passwords&#8221;.</p>
<p>The intro to the post makes it sound like all these sites are getting hacked because of Filezilla, but most of the hackings have nothing to do with Filezilla. It usually happens because of outdated content management software running on remote servers.</p>
<p>Filezilla is a great program, and there is nothing wrong with what it does. The only danger with the XML file is if someone steals your laptop. That is why laptop hard drives should be encrypted&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: USAA phishing emails &#171; Diary of a computer geek</title>
		<link>http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/comment-page-1/#comment-14449</link>
		<dc:creator>USAA phishing emails &#171; Diary of a computer geek</dc:creator>
		<pubDate>Sat, 24 Dec 2011 01:59:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=277#comment-14449</guid>
		<description>[...] Beware: FileZilla Doesn’t Protect Your Passwords  Share this:DiggFacebookRedditStumbleUponTwitterLike this:LikeBe the first to like this post.    Categories: Anti-virus and Anti-malware Tags: Malwarebytes, phishing, spam, Trojan.Zbot.CBCGen, USAA       Comments (5) Trackbacks (0) Leave a comment Trackback [...]</description>
		<content:encoded><![CDATA[<p>[...] Beware: FileZilla Doesn’t Protect Your Passwords  Share this:DiggFacebookRedditStumbleUponTwitterLike this:LikeBe the first to like this post.    Categories: Anti-virus and Anti-malware Tags: Malwarebytes, phishing, spam, Trojan.Zbot.CBCGen, USAA       Comments (5) Trackbacks (0) Leave a comment Trackback [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Krasi</title>
		<link>http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/comment-page-1/#comment-14174</link>
		<dc:creator>Krasi</dc:creator>
		<pubDate>Sat, 19 Nov 2011 19:52:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=277#comment-14174</guid>
		<description>For one I know that HostGator offers SSH and SFTP on their shared hosting and I use it all the time to protect my logins from being sniffed over the network.

It would have been nice if you had extended the article and included some good FTP clients that do encrypt the password.

Thanks</description>
		<content:encoded><![CDATA[<p>For one I know that HostGator offers SSH and SFTP on their shared hosting and I use it all the time to protect my logins from being sniffed over the network.</p>
<p>It would have been nice if you had extended the article and included some good FTP clients that do encrypt the password.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: FTP over SSL &#124; TerraNetwork</title>
		<link>http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/comment-page-1/#comment-14164</link>
		<dc:creator>FTP over SSL &#124; TerraNetwork</dc:creator>
		<pubDate>Fri, 18 Nov 2011 16:58:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=277#comment-14164</guid>
		<description>[...] Hence, even if the connection is securely encrypted with FTP over SSL, the stored FTP logins is easily obtained should the machine become infected with [...]</description>
		<content:encoded><![CDATA[<p>[...] Hence, even if the connection is securely encrypted with FTP over SSL, the stored FTP logins is easily obtained should the machine become infected with [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yereverluvinunclebert</title>
		<link>http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/comment-page-1/#comment-13998</link>
		<dc:creator>yereverluvinunclebert</dc:creator>
		<pubDate>Wed, 14 Sep 2011 11:07:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=277#comment-13998</guid>
		<description>I was trialling filezilla and configured 4 sites in the site manager. My PC was subsequently infected with a trojan (it happens) and all four sites were hacked and destroyed. All my other sites used WSFTP which has password encryption. None were hacked. Avoid using filezilla if you are using Windows in any form.</description>
		<content:encoded><![CDATA[<p>I was trialling filezilla and configured 4 sites in the site manager. My PC was subsequently infected with a trojan (it happens) and all four sites were hacked and destroyed. All my other sites used WSFTP which has password encryption. None were hacked. Avoid using filezilla if you are using Windows in any form.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dylan</title>
		<link>http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/comment-page-1/#comment-13942</link>
		<dc:creator>Dylan</dc:creator>
		<pubDate>Mon, 05 Sep 2011 10:16:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=277#comment-13942</guid>
		<description>Similar thing happened to me. An infected computer sent out Filezilla&#039;s plain text password file to a server where it was used to log in and infect all HTML and PHP files on my site.

Note, you are NOT SAFE WITH SFTP with Filezilla if you get Filezilla to hold the password as it will still be available in an unencrypted file! 

The solution is to use sftp with NO password and to use a SSH key; then simply load your private key into a key manager such as pageant. You can automatically and securely log in without needing to type in a password.</description>
		<content:encoded><![CDATA[<p>Similar thing happened to me. An infected computer sent out Filezilla&#8217;s plain text password file to a server where it was used to log in and infect all HTML and PHP files on my site.</p>
<p>Note, you are NOT SAFE WITH SFTP with Filezilla if you get Filezilla to hold the password as it will still be available in an unencrypted file! </p>
<p>The solution is to use sftp with NO password and to use a SSH key; then simply load your private key into a key manager such as pageant. You can automatically and securely log in without needing to type in a password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arthur</title>
		<link>http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/comment-page-1/#comment-13174</link>
		<dc:creator>Arthur</dc:creator>
		<pubDate>Fri, 20 May 2011 20:54:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=277#comment-13174</guid>
		<description>Just use Filezilla Portable via portableapps.com it&#039;s secure as it&#039;s portable and doesnt save any data on PC</description>
		<content:encoded><![CDATA[<p>Just use Filezilla Portable via portableapps.com it&#8217;s secure as it&#8217;s portable and doesnt save any data on PC</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dermott</title>
		<link>http://blog.unmaskparasites.com/2009/09/01/beware-filezilla-doesnt-protect-your-ftp-passwords/comment-page-1/#comment-12746</link>
		<dc:creator>Dermott</dc:creator>
		<pubDate>Sun, 06 Mar 2011 19:04:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.unmaskparasites.com/?p=277#comment-12746</guid>
		<description>But honestly, if you&#039;re going to blast your username/password pair in clear text across the NETWORK, who gives a flip if it&#039;s stored in a file on your hard drive?

The problem isn&#039;t FileZilla, it&#039;s FTP.</description>
		<content:encoded><![CDATA[<p>But honestly, if you&#8217;re going to blast your username/password pair in clear text across the NETWORK, who gives a flip if it&#8217;s stored in a file on your hard drive?</p>
<p>The problem isn&#8217;t FileZilla, it&#8217;s FTP.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

