{"id":7427,"date":"2026-03-27T09:15:02","date_gmt":"2026-03-27T08:15:02","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=7427"},"modified":"2026-06-08T13:06:19","modified_gmt":"2026-06-08T11:06:19","slug":"why-you-should-not-save-passwords-in-ftp-programs","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-you-should-not-save-passwords-in-ftp-programs\/","title":{"rendered":"Why you should not save passwords in FTP programs"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">Saving passwords directly within FTP clients (such as <a href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/configuring-filezilla-client-3-5-3\/\" data-type=\"link\" data-id=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/configuring-filezilla-client-3-5-3\/\">FileZilla<\/a>, Total Commander, or <a href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/winscp-configuration\/\" data-type=\"link\" data-id=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/winscp-configuration\/\">WinSCP<\/a>) is a significant security risk. While convenient, it creates a vulnerability that is frequently exploited by automated malware and targeted attacks.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-you-should-not-save-passwords-in-ftp-programs\/#Context\" >Context<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-you-should-not-save-passwords-in-ftp-programs\/#How_FTP_Credential_Theft_Works\" >How FTP Credential Theft Works<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-you-should-not-save-passwords-in-ftp-programs\/#Distinction_Saved_Passwords_vs_Active_Sessions\" >Distinction: Saved Passwords vs. Active Sessions<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-you-should-not-save-passwords-in-ftp-programs\/#Practical_Implications\" >Practical Implications<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/why-you-should-not-save-passwords-in-ftp-programs\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Context\"><\/span>Context<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">FTP programs often store saved credentials in plain text or weakly encrypted configuration files on your computer. If your local system is compromised by a Trojan, keylogger, or &#8220;stealer&#8221; virus, these files are the first targets. Once an attacker gains your FTP credentials, they have full access to modify, delete, or infect your website files.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_FTP_Credential_Theft_Works\"><\/span>How FTP Credential Theft Works<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<\/div>\n\n<div id=\"mybox-2920143211\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">When a virus infects a local computer, it typically follows a scripted path to compromise your web presence:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Extraction:<\/strong> The malware searches for the configuration folders of popular FTP programs and extracts saved usernames and passwords.<\/li>\n\n\n\n<li><strong>Automated Injection:<\/strong> The virus (or an attacker) logs into your hosting account and searches for core files like <code>index.php<\/code> or <code>index.html<\/code>.<\/li>\n\n\n\n<li><strong>Infection:<\/strong> Malicious code is automatically appended to these files. This code might redirect your visitors to phishing sites, steal their data, or use your server to send spam.<\/li>\n\n\n\n<li><strong>Persistence:<\/strong> Even if you clean your website, the virus on your computer can simply log back in and re-infect the files using the stolen password.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Distinction_Saved_Passwords_vs_Active_Sessions\"><\/span>Distinction: Saved Passwords vs. Active Sessions<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Saved Passwords:<\/strong> Credentials stored permanently in the software&#8217;s &#8220;Site Manager.&#8221; This is the highest risk.<\/li>\n\n\n\n<li><strong>Session Passwords:<\/strong> Entering your password manually each time you connect. The password remains in the computer&#8217;s volatile memory (RAM) only while the program is open, making it much harder for automated malware to steal.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Practical_Implications\"><\/span>Practical Implications<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you suspect your website has been compromised or your FTP credentials stolen, follow these steps immediately to regain control:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Scan your local computer:<\/strong> Run a deep antivirus scan on every device you use to manage your website. Do not change passwords until you are sure the local infection is removed.<\/li>\n\n\n\n<li><strong>Clear saved data:<\/strong> Delete all saved passwords from your FTP clients, browsers, and email programs.<\/li>\n\n\n\n<li><strong>Update mybox panel credentials:<\/strong> Change your main <strong>mybox<\/strong> account password and your individual FTP account passwords via the dashboard.<\/li>\n\n\n\n<li><strong>Clean the web account:<\/strong> In severe cases, you may need to delete the infected files and restore a clean version from a <strong>Standard<\/strong> or <strong>Archive Backup<\/strong>.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The security of your website is only as strong as the device you use to manage it. By choosing not to save passwords in your FTP client, you remove the primary &#8220;master key&#8221; that malware uses to hijack your hosting environment.<\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[10,23,25],"manual_kb_tag":[],"class_list":["post-7427","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-safety","manualknowledgebasecat-ftp","manualknowledgebasecat-hosting"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/7427","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":2,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/7427\/revisions"}],"predecessor-version":[{"id":7428,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/7427\/revisions\/7428"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=7427"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=7427"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=7427"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}