Saving passwords directly within FTP clients (such as FileZilla, Total Commander, or WinSCP) is a significant security risk. While convenient, it creates a vulnerability that is frequently exploited by automated malware and targeted attacks.
Table of Contents
Context
FTP programs often store saved credentials in plain text or weakly encrypted configuration files on your computer. If your local system is compromised by a Trojan, keylogger, or “stealer” virus, these files are the first targets. Once an attacker gains your FTP credentials, they have full access to modify, delete, or infect your website files.
How FTP Credential Theft Works
When a virus infects a local computer, it typically follows a scripted path to compromise your web presence:
- Extraction: The malware searches for the configuration folders of popular FTP programs and extracts saved usernames and passwords.
- Automated Injection: The virus (or an attacker) logs into your hosting account and searches for core files like
index.phporindex.html. - Infection: Malicious code is automatically appended to these files. This code might redirect your visitors to phishing sites, steal their data, or use your server to send spam.
- Persistence: Even if you clean your website, the virus on your computer can simply log back in and re-infect the files using the stolen password.
Distinction: Saved Passwords vs. Active Sessions
- Saved Passwords: Credentials stored permanently in the software’s “Site Manager.” This is the highest risk.
- Session Passwords: Entering your password manually each time you connect. The password remains in the computer’s volatile memory (RAM) only while the program is open, making it much harder for automated malware to steal.
Practical Implications
If you suspect your website has been compromised or your FTP credentials stolen, follow these steps immediately to regain control:
- Scan your local computer: Run a deep antivirus scan on every device you use to manage your website. Do not change passwords until you are sure the local infection is removed.
- Clear saved data: Delete all saved passwords from your FTP clients, browsers, and email programs.
- Update mybox panel credentials: Change your main mybox account password and your individual FTP account passwords via the dashboard.
- Clean the web account: In severe cases, you may need to delete the infected files and restore a clean version from a Standard or Archive Backup.
Summary
The security of your website is only as strong as the device you use to manage it. By choosing not to save passwords in your FTP client, you remove the primary “master key” that malware uses to hijack your hosting environment.