[FTP1.01] New "FTP Lock" Security Measure

Over the last year, there has been a substantial increase in the number of sites on the internet that have been hacked due to viruses (Gumblar or Troj/JSRedir-R FTP Viruses) that steal FTP credentials from user's home computers. The hackers then use these credentials to insert hidden code within websites.

To reduce the significant threat from these viruses pfpHosts.com has come up with a solution that protects websites. The solution is to lock FTP when it's not in use, making it extremely difficult for the hackers to infect your site via this route. To unlock FTP, customers will simply log into their pfpHosts.com control panel and click one button to unlock FTP for a period of time. FTP will then automatically lock again after the time period has expired. See diagram below:

Customers will also be able to nominate an IP address that has permanent FTP access, customers FTPing from that IP address will not have to unlock FTP. 

These security measures will ensure that the majority of sites have FTP locked, greatly reducing the risk of having your websites infected.


http://en.wikipedia.org/wiki/Gumblar

Was this answer helpful?

 Print this Article

Also Read

[FTP3.05] How do I set permissions on files and scripts?

Doing a CHMOD (changing a file's permissions) is the setting of access privileges for a file....

[FTP4.09] Unable to connect via FTP, the following error is being produced "530 Login failed. Perhaps your FTP access isn't unlocked?"

We have recently implemented an FTP locking system to improve security for all of our customers....

[FTP2.07] My extra FTP account doesn't seem to work with PHP scripts.

In theory, this should work without issues as all FTP users on a hosting account have the UID,...

[FTP2.11] I am unable to connect with FTP.

Your FTP account may be locked, for more information, consult the article on FTP locking. All...

[FTP2.01] I've uploaded my site on my hosting account but cannot see it?

As a first step, check the following points:- Is your domain on the correct name servers? To...