Simple Machines Community Forum

SMF Development => Bug Reports => Fixed or Bogus Bugs => Topic started by: kyleL on April 14, 2010, 07:32:53 PM

Title: FTP Information not stored once you enter it into ACP.
Post by: kyleL on April 14, 2010, 07:32:53 PM
Title: Re: FTP Information not stored once you enter it into ACP.
Post by: Norv on April 18, 2010, 05:10:44 PM
Thank you for taking the time to report this.

Personally, I don't think it's a bug. Instead, I would do the same (not store them) for security reasons. Every user credentials stored on the server mean more probability for spreading a problem like a hack or anything (when there is one).
Please note that a user's FTP account typically allows access to more than the forum directory: to everything they have in their hosting space. Including other sites, including (perhaps) other directories which are not even sites, but applications, logs, documents, anything. *IF* a SMF site or another site on your server gets hacked, there is a possibility the infection does not spread outside their directory. While if FTP credentials are also saved around there, or at their reach, this would allow for more probability that the attacker is able to grab them, thus everything in user's FTP account would be risked.

Not my call (the devs should decide on every bug), but I'm just explaining to you that, and why, I would not solve this... Sorry.