{"id":229,"date":"2025-12-17T10:20:33","date_gmt":"2025-12-17T09:20:33","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=229"},"modified":"2026-06-03T09:31:40","modified_gmt":"2026-06-03T07:31:40","slug":"ftp-client-how-to-take-care-of-security","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/","title":{"rendered":"FTP client &#8211; How to take care of security?"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">When using FTP clients to manage your website files, it is important to follow security best practices to protect your hosting account from unauthorized access and malware infections.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Over the years, malware authors have increasingly targeted FTP users through various forms of malicious software, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Keyloggers<\/li>\n\n\n\n<li>Password-stealing trojans<\/li>\n\n\n\n<li>Credential harvesters<\/li>\n\n\n\n<li>Automated website infection tools<\/li>\n<\/ul>\n\n\n\n<\/div>\n\n<div id=\"mybox-1352473104\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">These threats can infect a local computer and steal FTP credentials stored in popular FTP applications.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/#How_FTP_Credentials_Are_Stolen\" >How FTP Credentials Are Stolen<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/#Saved_Passwords\" >Saved Passwords<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/#Keystroke_Monitoring\" >Keystroke Monitoring<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/#What_Happens_After_Credentials_Are_Stolen\" >What Happens After Credentials Are Stolen?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/#Recommended_Security_Practices\" >Recommended Security Practices<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/#Do_Not_Save_FTP_Passwords\" >Do Not Save FTP Passwords<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/#Use_SFTP_Instead_of_FTP\" >Use SFTP Instead of FTP<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/#Keep_Your_Computer_Protected\" >Keep Your Computer Protected<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/#Use_Strong_Passwords\" >Use Strong Passwords<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/#Regularly_Scan_Your_Website\" >Regularly Scan Your Website<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/#Change_Passwords_After_a_Security_Incident\" >Change Passwords After a Security Incident<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/ftp-client-how-to-take-care-of-security\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_FTP_Credentials_Are_Stolen\"><\/span>How FTP Credentials Are Stolen<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Malware commonly obtains FTP credentials through one of the following methods:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Saved_Passwords\"><\/span>Saved Passwords<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Many FTP clients allow users to save connection details, including passwords.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Popular applications affected by this type of attack include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>FileZilla<\/li>\n\n\n\n<li>WinSCP<\/li>\n\n\n\n<li>Total Commander<\/li>\n\n\n\n<li>Cyberduck<\/li>\n\n\n\n<li>Other FTP\/SFTP clients<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If malware gains access to the computer, it may extract saved credentials directly from the application&#8217;s configuration files.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Keystroke_Monitoring\"><\/span>Keystroke Monitoring<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some malware acts as a keylogger and records everything typed on the keyboard, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>FTP usernames<\/li>\n\n\n\n<li>FTP passwords<\/li>\n\n\n\n<li>Control panel logins<\/li>\n\n\n\n<li>Email passwords<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The captured information is then transmitted to the attacker.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Happens_After_Credentials_Are_Stolen\"><\/span>What Happens After Credentials Are Stolen?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Once an attacker obtains FTP access, they may:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Inject malicious code into website files.<\/li>\n\n\n\n<li>Modify <code>index.php<\/code>, <code>index.html<\/code>, or other core files.<\/li>\n\n\n\n<li>Insert spam links.<\/li>\n\n\n\n<li>Redirect visitors to malicious websites.<\/li>\n\n\n\n<li>Distribute malware through your website.<\/li>\n\n\n\n<li>Create backdoors for future access.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In some cases, automated malware performs these actions without any direct involvement from a human attacker.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Recommended_Security_Practices\"><\/span>Recommended Security Practices<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Do_Not_Save_FTP_Passwords\"><\/span>Do Not Save FTP Passwords<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As a security best practice, avoid storing FTP passwords in your FTP client whenever possible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Enter the password manually when connecting.<\/li>\n\n\n\n<li>Disable password saving features if available.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This significantly reduces the risk of credential theft if the computer becomes infected.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Use_SFTP_Instead_of_FTP\"><\/span>Use SFTP Instead of FTP<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Whenever possible, use:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>SFTP (SSH File Transfer Protocol)<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">instead of standard FTP.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Benefits include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Encrypted authentication<\/li>\n\n\n\n<li>Encrypted file transfers<\/li>\n\n\n\n<li>Better protection against network interception<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Keep_Your_Computer_Protected\"><\/span>Keep Your Computer Protected<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Ensure that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Your operating system is updated.<\/li>\n\n\n\n<li>Antivirus software is installed and active.<\/li>\n\n\n\n<li>Anti-malware protection is regularly updated.<\/li>\n\n\n\n<li>Suspicious software is not installed.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Use_Strong_Passwords\"><\/span>Use Strong Passwords<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">FTP passwords should:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Be unique<\/li>\n\n\n\n<li>Contain at least 12\u201316 characters<\/li>\n\n\n\n<li>Include uppercase and lowercase letters<\/li>\n\n\n\n<li>Include numbers and special characters<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Avoid reusing passwords from other services.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Regularly_Scan_Your_Website\"><\/span>Regularly Scan Your Website<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Periodically review your website files for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Unexpected modifications<\/li>\n\n\n\n<li>Unknown PHP files<\/li>\n\n\n\n<li>Suspicious redirects<\/li>\n\n\n\n<li>Obfuscated code<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Early detection can help prevent larger security incidents.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Change_Passwords_After_a_Security_Incident\"><\/span>Change Passwords After a Security Incident<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you suspect that your computer has been infected or that your FTP credentials may have been exposed:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Scan and clean the infected device.<\/li>\n\n\n\n<li>Change all FTP passwords immediately.<\/li>\n\n\n\n<li>Review website files for unauthorized changes.<\/li>\n\n\n\n<li>Update CMS software, plugins, and themes.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To improve the security of your hosting account:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Avoid saving FTP passwords in client applications.<\/li>\n\n\n\n<li>Use SFTP whenever possible.<\/li>\n\n\n\n<li>Keep your computer protected with updated security software.<\/li>\n\n\n\n<li>Use strong, unique passwords.<\/li>\n\n\n\n<li>Monitor your website for unauthorized modifications.<\/li>\n\n\n\n<li>Change credentials immediately if a compromise is suspected.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Following these recommendations can significantly reduce the risk of website infections caused by stolen FTP credentials.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[23,25],"manual_kb_tag":[3845,516,745,1674,1710,1759,3841,3842,3843,3844],"class_list":["post-229","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-ftp","manualknowledgebasecat-hosting","manual_kb_tag-total-commander","manual_kb_tag-filezilla","manual_kb_tag-malware","manual_kb_tag-credential-theft","manual_kb_tag-ftp-security","manual_kb_tag-password-security","manual_kb_tag-keylogger","manual_kb_tag-password-theft","manual_kb_tag-saved-passwords","manual_kb_tag-ftp-clients"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/229","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":2,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/229\/revisions"}],"predecessor-version":[{"id":4895,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/229\/revisions\/4895"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=229"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=229"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}