Tuesday, June 22, 2010

CrushFTP 5.1.1 Released!

New:

***initial support for UDP tunneling for faster transfers (Enterprise Licensed Customers only)

***UDP support includes FTP proxy, SFTP proxy, and HTTP/TCP proxies (Enterprise Licensed Customers only)

***warns if you use different versions of CrushFTP for remote admin and actual serving

***added case sensitive filtering flag on dir listings

***added flag for controlling FTP proxy mode on non standard FTP dir listings

***defaults to Binary mode if the using FTP and the user never specified (flag can control this)

***significantly improved proxy performance

***folder monitors can now run in intervals of seconds if the value is negative

***added flag to allow disabling the stats DB engine

***fixed memory consumption scenario for FTP transfers

***set AES ciphers to be higher priority by default

***added support for higher strength AES ciphers in SFTP if your Java has the right policy files

***added support for automatically resuming failed uploads or downloads with the FTP proxy

***added mdtm_gmt flag to make MDTM use GMT format for dates

***alert's can now execute a plugin by specifying it in the "To:" header. Example: PLUGIN:CrushTask

***added flag for determining if reports should be emailed in HTML or Plain Text mode

***added support for SFTP key renegotiations


Fixes:

***A CRITICAL BUG in CrushFTP 5.1.0_37-5.1.0_45 was fixed. (Denial of Service)

***fixed bug saving changes to the connection groups

***fixed bug where the last window size wasn't being preserved

***fixed log location filename

***fixes bugs when reading in ASCII mode to prevent character translation

***fixes potential port conflict bugs with port race conditions on Solaris

***fixed bug with the SCP handling of flags

***fixed bug creating the default user in MySQL

***fixed idle handling for HTTP sessions

***fixed bugs with Safari 5

***fixed bug with Flash 10.1 removing menu items

***fixed bug with HTTP sessions behind a reverse proxy

***fixed bug with owner/group/priv information with non ASCII filenames


CrushFTP 5.1.0_37 to CrushFTP 5.1.0_45 URGENT BUG FIX!

If you downloaded CrushFTP from the time period 6/11/2010 to 6/22/2010 your version of CrushFTP will fall in this range.

Please update your copy of CrushFTP5 immediately to the latest build by selecting check for update from the File menu. Click the button to check for update, and answer YES to update even though you have the latest version. Tonight I will update my official version number forcing everyone to see the new update.

The bug is specific to CrushFTP 5, and causes a Denial of Service where CrushFTP is unusable. Do not wait to see if the bug can effect you, rather update immediately if your version ends in _37 through _45.

This is a critical bug.

Please update if you have those versions. Sorry I'm not going to give more info on the bug, but I don't want people accidentally, or maliciously to hurt themselves or others.

Sorry for the inconvenience.

--Ben

Monday, May 10, 2010

CrushFTP 5.1.0 has been Released!

Finally, a new official public version. Lots of testing and bug fixes went into making this version.

New:
***uses fewer threads for all sessions
***client certificate authentication is now supported for FTPS as well as HTTPS
***improves WebInterface to display logos, welcome messages and honor some color customizations
***added control to block access to specific directories or files matching a pattern
***improved server prefs GUI to be less confusing on what "Server Groups" do
***added default for WebInterface to hide the upload method choice
***added defaults for WebInterface sharing, and allowing uploads
***supports recursive MKDIR command in FTP now
***added customization to force slideshow only mode
***added browse and test buttons for DB setup on the User Config tab
***windows service will now work in 64bit mode instead of 32bit mode
***faster exiting of failed remote admin sessions
***added support for dumb proxy mode
***SQL compatibility improvements
***removes temp files when using remote admin mode from a web browser
***added flag for disabling an account in the user manager
***added additional plugin hooks to monitor and control CrushFTP
***added flag to make events be able to be run immediately (_NO_DELAY at the end of the event name)
***added support for SFTP public key files being stored in the user manager field
***allows for multiple copies of CrushFTP to technically be run from the same machine
***now propagates error messages back to WebInterface or SFTP client if an upload fails.
***improved servu import to capture notes field

Fixes:
***WebInterface compatibility fixes
***bug fixes for webdav clients
***bug fix for editing inline plugin info in user manager
***fixed who downloaded report to only show downloaded files
***bug fixes for the WebInterface sharing feature
***bug fix for downloading PDF files with Adobe Reader browser plugin
***bug fix for event handling processing a file multiple times
***fixed bug when writing files in encrypted mode
***fixed bug for making previews of images when not on the C drive
***fixed bug with chmod in SFTP
***fixed bugs with CCC command in FTPS mode
***fixed bug with IIS FTP proxying
***fixed compatibility with Adobe Contribute and WebDav
***fixed bug with chunked HTTP tunneling
***fixed potential memory leak when in proxy mode
***fixed bug with importing CrushFTP 4 user databases to CrushFTP 5
***fixed bugs with SFTP proxy handling of files and directories

Tuesday, March 16, 2010

FTPS Client based authentication

The HTTPS server in CrushFTP has been able to authenticate users by a client based certificate allowing for auto user/password authentication based solely on the certificate installed in the browser.

Technically, the FTP protocol can do this as well, and so I have added support for it with the FTP protocol too. I verified this using the command line client "curl". Its still a bit of a pain dealing with all the certificates, so I'll be writing up some entries in my Wiki to help people with the process.

The summary? CrushFTP now supports FTPS client based certificates for authentication where the common name is the username. The cert the user provides must exist in your trust store file as a certificate that was issued from your server, or it won't be accepted.

Friday, March 5, 2010

CrushFTP 5 WebInterface

The flash WebInterface is finally getting some attention. I've enabled the header, logos, and some other customizations for it.

I'm working on the flash stuff pretty regularly now. Its still not the way I want it to be, but its definitely getting closer.

More features to come soon for the slideshow ability on photos in it too.

CrushSync 1.6 was just posted.

My favorite part is its self update. Now I can set my parents computer to self update to newer versions automatically without me getting involved. See my FAQ on how to configure self updating on CrushSync: http://www.crushsync.com/faq.html


New:

***improved logging to have more meaningful data

***added log rolling ability to keep logs files from growing to big

***added ability for OS X to do self updates


Fixed:

***fixed schedule bug where schedules may not run

***fixed bug so self updating will work

***fixed bug so post script commands will complete


Thursday, February 25, 2010

Just posted a new version of CrushFTP 4 and CrushFTP 5

New:

***will act as CrushFTP 5 is CrushFTP detects you meant to start CrushFTP5 but forgot the flag (linux)

***uses new events system for more reliable event execution

***made it easier for generating Previews

***can now set the title on the login page

***added additional support for dump proxy mode in CrushFTP when dealing with bad FTP servers

***folder monitor can now call third party plugins (CrushTask)

***added support for allowing uploading to temp accounts

***added additional hooks for plugins

***changed dir filtering to use regex (partially)

***added flag to be able to start Crush with all ports stopped

***WebDAV is now supported on Windows Vista / 7

***WebDAV now passes most of the 'litmus' tests.

***some plugins can now be created inline in the UserManager instead of just globally in the server prefs

***creates groups in CrushFTP 5 when importing CrushFTP 4 users

***added variable %user_dir% that does not include the root directory of a user

***added ability to set a alternate source port for active mode connections


Fixes:

***fixed bug with ServerBeat not being disabled properly

***fixed bug with inheriting the user/group/privs in OS X and Linux when writing a new file.

***fixed bug with scp handling multiple uploads per connection

***fixed bugs with generating Previews on Windows

***fixed bugs with Flash and UTF8 characters (another work around)

***fixed bug with CrushUploader uploading files

***fixed bug with backing up prefs.xml, and restoring a backup file if a main one fails

***fixed bugs with Custom VFS's by third parties

***fixed bug where modified dates were lost when you copied and pasted files in the WebInterface

***fixed bugs with editing temp accounts when using remote admin mode

***fixed bug with lowres downloads of images

***fixed bug with UTF8 characters in emails

***fixed bug with a memory leak

***fixed bug where files coulee be left in use

***fixed admin user creation to write file in the CrushFTP 5 default location

***fixed bug where uploads seemed to be failing even though they were not

***fixed bug with the IP in response to PASV

***fixed bug with timeouts for hammer banning

***fixed bug with the folder monitor GUI

***fixed bug with CCC synchronization

***fixed bug with blocking WebDAV connections

***fixed bug with empty directory listings

***fixed bug with logging in and out using different user accounts within the same browser session

***fixed bug with linked events

***fixed bug with miniURLs and the default flash/html mode