Hua Li's Library tagged → View Popular
15 Dec 09
警惕 FileZilla Client 的密码安全问题
-
今天意外发现 FileZilla 一个严重的安全问题,FTP密码竟然是以明文形式存放在磁盘文件里!
以下三个文件包含你的FTP密码:
复制内容到剪贴板代码:
filezilla.xml - Stores most recent server info including password in plaintext.
recentservers.xml - Stores all recent server info including password in plaintext.
sitemanager.xml - Stores all saved sites server info including password in plaintext.
这些文件通常存放于这些目录下:
复制内容到剪贴板代码:
Windows XP/2K: "C:\Documents and Settings\username\Application Data\FileZilla"
Windows Vista: "C:\Users\username\AppData\Roaming\FileZilla\"
Linux: "/home/username/.filezilla/"
真是昏,密码直接以未加密的明文形式存放于 XML 文件的 < Pass>YourPassword</Pass> 内。就是随便用个简单的对称算法甚至 XOR 加密都比赤裸裸的放着强啊!
01 Aug 09
Darik's Boot And Nuke | Hard Drive Disk Wipe
Darik's Boot and Nuke ("DBAN") is a self-contained boot disk that securely wipes the hard disks of most computers. DBAN will automatically and completely delete the contents of any hard disk that it can detect, which makes it an appropriate utility for bulk or emergency data destruction.
Selected Tags
Related Tags
Sponsored Links
Ads by Google
Top Contributors
Groups interested in security
Related Lists on Diigo
-
Online Security
Everything related to onlin...
Items: 4 | Visits: 137
Created by: Call Me What You Want
-
Free Security Software
Free security software to h...
Items: 22 | Visits: 113
Created by: Matt G.
-
Defensive Web Programming
Links that came up during S...
Items: 16 | Visits: 181
Created by: Joel Bennett
Diigo is about better ways to research, share and collaborate on information. Learn more »
Join Diigo
