Archives: June 28, 2023

Syncplify Server! has no known vulnerabilities in the NIST NVD

In the aftermath of the already infamous MOVEit hack, which is only the most recent one in a long list of competitors exposing their customers data, we would like to take this opportunity to underscore a few important facts about Syncplify Server!

In fact, Syncplify Server! is the only enterprise-grade, commercial SFTP server on the market that has never been hacked, and has literally zero vulnerabilities listed in the NIST NVD, which is the National Vulnerability Database owned and operated by the National Institute of Standards and Technology.

But hey, it’s easy to toss around such a bold claim without proof, right? That’s why we’re not asking you to take our word for it. This is something you can verify yourself.

How? Here you go:

  • Point your browser to the NIST NVD website search page
  • Type in Syncplify Server! or even just Syncplify, and verify that no vulnerabilities are found (here’s a direct link if you don’t want to type)
  • Now go back to the NIST NVD search page and try to search for any of our competitors; chances are anyone you search for will have a list of known vulnerabilities hackers can, have, and will exploit to gain access to your data

This is not a random result; where many of our competitors have chosen to give in to flashy UIs and unreasonable support for old/legacy algorithms now obsolete and proven weak, we have never been afraid to lead our customers onto a path of true security without trade-offs.

Stay safe, choose unrelenting security, use Syncplify.


Syncplify Server! v6.2.1 released

Importance of this update: MINOR
Fixed
  • All file transfer operations now correctly log the relative path of the file that was transferred

IMPORTANT NOTE: those who are running the “worker” system service under a different account (not System or LocalSystem) will need to re-configure the service to run under such account after upgrading from any version number <= 6.1.12)

Upgrading from v6.x.y is a simple and fairly automatic process: simply download the latest version from the official download page, and install it over the existing version, all of your settings and license will be kept.

If, instead, you’re upgrading from an older (v4/v5) version, you find the upgrade instructions in our knowledge base.

Thank you all for trusting our software with your secure file transfers!


Syncplify Server! v6.2.0 released 🔥

Importance of this update: HIGHEST
Improved
  • Removed dependency on nssm.exe to reduce the number of false-positives from certain antivirus and antimalware software: all components of the Windows version of our software now run as native Windows system service (all Linux versions were already native system services)

IMPORTANT NOTE: those who are running the “worker” system service under a different account (not System or LocalSystem) will need to re-configure the service to run under such account after upgrading from any version number <= 6.1.12)

Upgrading from v6.x.y is a simple and fairly automatic process: simply download the latest version from the official download page, and install it over the existing version, all of your settings and license will be kept.

If, instead, you’re upgrading from an older (v4/v5) version, you find the upgrade instructions in our knowledge base.

Thank you all for trusting our software with your secure file transfers!


Syncplify Server! v6.1.12 released

Importance of this update: MINOR
Fixed
  • Fixed first activation of 2FA for additional SuperAdmin accounts from within the SuperAdmin account that creates them (self-enrollment already worked as expected)

Upgrading from v6.x.y is a simple and fairly automatic process: simply download the latest version from the official download page, and install it over the existing version, all of your settings and license will be kept.

If, instead, you’re upgrading from an older (v4/v5) version, you find the upgrade instructions in our knowledge base.

Thank you all for trusting our software with your secure file transfers!


Syncplify Server! v6.1.11 released 🚨

Importance of this update: VERY HIGH
Fixed
  • Editing of bindings for HA (high-availability) deployments now works as expected even when one of the nodes was not initialized in the first place
New
  • The new SNI implementation that was introduced about a month ago in the Web/REST service has now been extended and incorporated into the “worker” service as well; this makes certificate management far easier, and comes with the additional advantage of not having to restart the system service(s) anymore when you update/change your X.509 certificate(s)

Upgrading from v6.x.y is a simple and fairly automatic process: simply download the latest version from the official download page, and install it over the existing version, all of your settings and license will be kept.

If, instead, you’re upgrading from an older (v4/v5) version, you find the upgrade instructions in our knowledge base.

Thank you all for trusting our software with your secure file transfers!


False-positives on VirusTotal

One-liner: yes, those are false-positives, and our software is 100% safe and virus-free!

Some users have reported that when they scan our Syncplify Server! installer with multiple engines using VirusTotal, they occasionally receive one or two warning (out of 70+ antivirus engines that VirusTotal employs).

It was out duty to investigate.

First and foremost, let us confirm, for everyone’s peace of mind, that our software is absolutely virus-free and safe to use, so those are so-called “false positives”.

Why is it happening? We narrowed it down to the fact that in order to run our software as a Windows system service, we take advantage of a little piece of 3rd-party software called NSSM.

NSSM is a tiny piece of software that allows any console (stdin/stdout) application to be executed as a system service in Windows. This was not developed by Syncplify, but we adopted it because of the great flexibility and reliability it offers. Sadly, we learned that some antivirus engines flag this little executable as suspicious (it not flat-out as malware).

We are, therefore, hard at work to drop the need for NSSM, and turn the Windows version of our software into a set of native system services, thus bypassing the issue entirely.

As always, thank you for your trust and for your patience.


Syncplify Server! v6.1.10 released 🔥

Importance of this update: HIGH
Fixed
  • The Zip function in our scripting engine now can correctly create encrypted zip archives that are compatible with both Windows and Linux OSs
  • Editing of bindings for HA (high-availability) deployments now works as expected
  • An occasional false-positive in closing idle sessions has been eliminated
New
  • Added more debug and trace logging for quota management
  • JWT (auth token) management in WebClient! has been completely redesigned for better security and broader client support
  • Multiple WebClient! shared objects (files/directories) can now be accessed concurrently in different tabs/windows in the same browser process
  • Added support for “subject alternative names” in our SNI implementation
  • Added a ton of trace-level logging for LDAP queries

Upgrading from v6.x.y is a simple and fairly automatic process: simply download the latest version from the official download page, and install it over the existing version, all of your settings and license will be kept.

If, instead, you’re upgrading from an older (v4/v5) version, you find the upgrade instructions in our knowledge base.

Thank you all for trusting our software with your secure file transfers!


Syncplify Server! v6.1.9 released

Importance of this update: NORMAL
Fixed
  • The Zip function in the scripting language now correctly supports Windows and Linux compatible encrypted zip archives
  • Several minor glitches in the UIs (SuperAdmin and Admin) have been fixed, if you experienced some issues with the UIs this is definitely an update you want to perform

Upgrading from v6.x.y is a simple and fairly automatic process: simply download the latest version from the official download page, and install it over the existing version, all of your settings and license will be kept.

If, instead, you’re upgrading from an older (v4/v5) version, you find the upgrade instructions in our knowledge base.

Thank you all for trusting our software with your secure file transfers!