31 votes

Filezilla bundles malware; dev doubles down on "false positive"

15 comments

  1. [5]
    SaucedButLeaking
    Link
    Several users in the linked forum thread raise issues of very malicious-seeming behavior (at the very least it's obfuscation, which I really don't trust in "bundled software"). Anyone have a good...

    Several users in the linked forum thread raise issues of very malicious-seeming behavior (at the very least it's obfuscation, which I really don't trust in "bundled software").

    Anyone have a good alternative?

    8 votes
    1. [4]
      merick
      Link Parent
      Most people I know are using WinSCP instead. I haven't used it more than a couple of times, but it seems to do the job just fine and I've heard many good things about it.

      Most people I know are using WinSCP instead. I haven't used it more than a couple of times, but it seems to do the job just fine and I've heard many good things about it.

      13 votes
      1. [2]
        Neverland
        (edited )
        Link Parent
        I use WinSCP sometimes. It's works just fine and if you already use PuTTY for SSH, then WinSCP will import all of your existing connection profiles. edit: garbage phrasing

        I use WinSCP sometimes. It's works just fine and if you already use PuTTY for SSH, then WinSCP will import all of your existing connection profiles.

        edit: garbage phrasing

        8 votes
        1. arghdos
          Link Parent
          Seconded, the only thing I don't care for in WinSCP is that there's no native option for X11 tunneling. Instead I have to go googling to try to remember the cmd-line argument to start PuTTY w /...

          Seconded, the only thing I don't care for in WinSCP is that there's no native option for X11 tunneling. Instead I have to go googling to try to remember the cmd-line argument to start PuTTY w / X11 enabled

          2 votes
      2. clerical_terrors
        Link Parent
        WinSCP does almost everything Filezilla does just as well, been using it for years and never had any issues.

        WinSCP does almost everything Filezilla does just as well, been using it for years and never had any issues.

        3 votes
  2. cws
    Link
    I actually recommended FileZilla earlier this week to a friend of mine so he could have access to my Seedbox. I saw it was packaging software alongside the installer and opted to setup WinSCP for...

    I actually recommended FileZilla earlier this week to a friend of mine so he could have access to my Seedbox. I saw it was packaging software alongside the installer and opted to setup WinSCP for him instead. Having the box mounted as a volume is much easier anyways.

    4 votes
  3. Luca
    Link
    Times like this I'm happy I pretty much exclusively use CLI tools for remote file management

    Times like this I'm happy I pretty much exclusively use CLI tools for remote file management

    3 votes
  4. [5]
    Pilgrim
    Link
    Can anyone recommend and alternative for Ubuntu with similar bookmarking features?

    Can anyone recommend and alternative for Ubuntu with similar bookmarking features?

    3 votes
    1. [4]
      userexec
      Link Parent
      Seconded. Mostly Linux user here who's always used FileZilla for both personal and work purposes. It was always just in the repos and did the job no complaints so I've never really given it a...

      Seconded. Mostly Linux user here who's always used FileZilla for both personal and work purposes. It was always just in the repos and did the job no complaints so I've never really given it a second thought. I'd like to hear if anyone's opinionated on what they use for this and why.

      2 votes
      1. [2]
        what
        Link Parent
        Just adding in case anyone doesn’t know, FileZilla is fine on Linux, since every distribution builds it from source. Of course, everyone should stop using it ASAP, but it’s not super urgent on...

        Just adding in case anyone doesn’t know, FileZilla is fine on Linux, since every distribution builds it from source.

        Of course, everyone should stop using it ASAP, but it’s not super urgent on Linux for the time being.

        4 votes
        1. Pilgrim
          Link Parent
          Well that's a relief. Thank you for the comment.

          Well that's a relief. Thank you for the comment.

          1 vote
      2. teaearlgraycold
        Link Parent
        Sometimes it's nice to have a GUI but for most SFTP actions I need to perform scp does the job just fine.

        Sometimes it's nice to have a GUI but for most SFTP actions I need to perform scp does the job just fine.

  5. insomnic
    Link
    Ran into this last week and was shocked AV was kicking out the installer. I figured it was just a false positive until days went by and it was still happening --- went with WinSCP for Win and...

    Ran into this last week and was shocked AV was kicking out the installer. I figured it was just a false positive until days went by and it was still happening --- went with WinSCP for Win and CyberDuck for Mac instead.

    1 vote
  6. [2]
    anti
    Link
    What is the bundled software? It is not necessarily malware. It may be adware or some toolbar type bullshit. The software is probably benign, but not something most people want on their PC.

    What is the bundled software?

    It is not necessarily malware. It may be adware or some toolbar type bullshit.

    The software is probably benign, but not something most people want on their PC.

    1. patience_limited
      Link Parent
      These days, it's legitimate to regard "adware" as malware since you have no idea what executables are being syndicated. Widespread malware outbreaks have arisen through apparently legitimate ad...

      These days, it's legitimate to regard "adware" as malware since you have no idea what executables are being syndicated. Widespread malware outbreaks have arisen through apparently legitimate ad networks, and there's no effective legal control, prosecution or liability. It's not safe to install, period.

      I'm horrified that FileZilla has gone to the dark side this way; I've actually paid for the Pro product previously because I wanted to comply with the licensing policy for business use.

      3 votes