- Filezilla stores all sites username and passwords in clear text in a fixed location: %APPDATA%\fielzilla\sitemanager.xml
- Even if you do not use site manager to save your passwords, Filezilla saves all "quick connections" to a file "recentservers.xml", again with all username and passwords in clear text.
- A bug has been filed for Filezilla to encrypt the passwords with a master password over 3 years ago, yet no action has been taken.
Switch to "WinSCP", which is also open source, and allow you to encrypt all stored passwords with a master password.
Thanks.................dude
ReplyDeleteWOW! This is so true, I can't believe my eyes!!
ReplyDeleteJust checked this location and found all my passwords clean and open to any sniffer I might possibly have.
Thank you man!!!
Just make sitemanager.xml recentservers.xml files "read-only" problem solved doh.
ReplyDelete