When using FTP clients to manage your website files, it is important to follow security best practices to protect your hosting account from unauthorized access and malware infections.
Over the years, malware authors have increasingly targeted FTP users through various forms of malicious software, including:
- Keyloggers
- Password-stealing trojans
- Credential harvesters
- Automated website infection tools
These threats can infect a local computer and steal FTP credentials stored in popular FTP applications.
Table of Contents
How FTP Credentials Are Stolen
Malware commonly obtains FTP credentials through one of the following methods:
Saved Passwords
Many FTP clients allow users to save connection details, including passwords.
Popular applications affected by this type of attack include:
- FileZilla
- WinSCP
- Total Commander
- Cyberduck
- Other FTP/SFTP clients
If malware gains access to the computer, it may extract saved credentials directly from the application’s configuration files.
Keystroke Monitoring
Some malware acts as a keylogger and records everything typed on the keyboard, including:
- FTP usernames
- FTP passwords
- Control panel logins
- Email passwords
The captured information is then transmitted to the attacker.
What Happens After Credentials Are Stolen?
Once an attacker obtains FTP access, they may:
- Inject malicious code into website files.
- Modify
index.php,index.html, or other core files. - Insert spam links.
- Redirect visitors to malicious websites.
- Distribute malware through your website.
- Create backdoors for future access.
In some cases, automated malware performs these actions without any direct involvement from a human attacker.
Recommended Security Practices
Do Not Save FTP Passwords
As a security best practice, avoid storing FTP passwords in your FTP client whenever possible.
Instead:
- Enter the password manually when connecting.
- Disable password saving features if available.
This significantly reduces the risk of credential theft if the computer becomes infected.
Use SFTP Instead of FTP
Whenever possible, use:
SFTP (SSH File Transfer Protocol) instead of standard FTP.
Benefits include:
- Encrypted authentication
- Encrypted file transfers
- Better protection against network interception
Keep Your Computer Protected
Ensure that:
- Your operating system is updated.
- Antivirus software is installed and active.
- Anti-malware protection is regularly updated.
- Suspicious software is not installed.
Use Strong Passwords
FTP passwords should:
- Be unique
- Contain at least 12–16 characters
- Include uppercase and lowercase letters
- Include numbers and special characters
Avoid reusing passwords from other services.
Regularly Scan Your Website
Periodically review your website files for:
- Unexpected modifications
- Unknown PHP files
- Suspicious redirects
- Obfuscated code
Early detection can help prevent larger security incidents.
Change Passwords After a Security Incident
If you suspect that your computer has been infected or that your FTP credentials may have been exposed:
- Scan and clean the infected device.
- Change all FTP passwords immediately.
- Review website files for unauthorized changes.
- Update CMS software, plugins, and themes.
Summary
To improve the security of your hosting account:
- Avoid saving FTP passwords in client applications.
- Use SFTP whenever possible.
- Keep your computer protected with updated security software.
- Use strong, unique passwords.
- Monitor your website for unauthorized modifications.
- Change credentials immediately if a compromise is suspected.
Following these recommendations can significantly reduce the risk of website infections caused by stolen FTP credentials.