SecureFX® 2.0.5 Official -- January 21, 2003 Copyright © 1995-2003 VanDyke Software, Inc. All rights reserved. This file contains a SecureFX product history. It includes lists of new features, changes, and bug fixes sorted by release. For a product description, installation notes, registration and contact information, please refer to Readme.txt (downloaded with this installation). Changes in SecureFX 2.0.5 Official -- January 21, 2003 ------------------------------------------------------ Bug fixes: - SecureFX failed to scrub usernames, passwords, and passphrases from memory after use. Scrubbing memory prevents an attacker with access to memory or a memory dump from getting authentication information. Changes in SecureFX 2.0.4 Official -- September 5, 2002 ------------------------------------------------------- Bug fixes: - Resuming SFTP transfers resulted in corruption of the file that was being transferred. - Right-clicking on a file in the remote window, choosing download, and selecting the root of a drive on the local machine would fail to download the file. - SecureFX crashed if the tree view was re-enabled when the focus was in the log window. - SecureFX incorrectly parsed file listings when connected to an OS/400 server causing files to be uploaded into the wrong directory. Changes in SecureFX 2.0.3 Official -- July 9, 2002 -------------------------------------------------- Changes: - Enabled support for keeping connections alive when using SFTP as the protocol. - Changed the way the version string is sent to the SSH2 server because some SSH Communications servers misdetected SecureFX's version string as another older client. This caused the servers to enable compatibility modes that they should not have, leading to interoperability problems. Bug fixes: - Under OS/400 SecureFX was misinterpreting some library names as member names which caused upload transfers to fail. - Drag and drop of files from Windows Explorer under Windows XP was failing. Changes in SecureFX 2.0.2 Official -- June 11, 2002 --------------------------------------------------- Bug fixes: - The log view was slow when the log window buffer was full and SecureFX had to scroll the log text. - SFXCL returned an ambiguous error when connecting to VanDyke VShell and the maximum number of users were already logged on. Changes in SecureFX 2.0.1 Official -- March 26, 2002 ---------------------------------------------------- Bug fixes: - Relinked with the latest zlib compression library, fixing a problem that may manifest itself as a vulnerability that could allow an attacker to conduct a denial-of-service attack, gather information, or execute arbitrary code. For more information see: http://www.kb.cert.org/vuls/id/368819 . - Changing the buffer size for SFTP writes improved uploads to OpenSSH servers by a factor of five to ten. - Relentless retry for FTP connections would fail to automatically reconnect for some error codes. Changed the FTP connections to retry whenever the connection failed regardless of the error. - SFXCL.EXE would still prompt for passwords when the host and password information was given in URL format. - SFXCL.EXE would ignore the port specified in the sftp:// syntax. - The log view visibility setting was not saved. Changes in SecureFX 2.0 Official -- February 19, 2002 ----------------------------------------------------- - No changes Changes in SecureFX 2.0 (Beta 5) -- February 12, 2002 ----------------------------------------------------- Bug fixes: - When an FTP session was changed to "FTP over SSH2" the password was not being cleared. - "Relentless" retries were aborted if a reconnection occurred while a prompt was being displayed. - The VanDyke logo bitmap in the evaluation dialog was not sized properly with large fonts selected. - Clarified the License error displayed when entering a license for an older version of SecureFX. - Manual Uploads and uploads from the command line would fail to transfer if the /Overwrite Older flag was used. Changes in SecureFX 2.0 (Beta 4) -- January 29, 2002 ---------------------------------------------------- New features: - Added "relentless" file transfer, which will automatically reconnect when a connection is broken and resume at the point the transfer was broken. This feature is not supported for server-to-server transfers. Bug fixes: - Passwords were not correctly saved when using the New Session Wizard to create SFTP sessions. - For FTP sessions, connecting without saving the password resulted in a blank password being saved. This caused subsequent connections to fail. Changes in SecureFX 2.0 (Beta 3) -- January 17, 2002 ---------------------------------------------------- New features: - SecureFX now allows blank passwords. Bug fixes: - SecureFX had difficulty connecting to older (2.5.x) OpenSSH servers that incorrectly configured Group Exchange (GEX). - Host keys were not stored in the "HostKeyDatabase" folder if the session database was migrated from AbsoluteFTP to SecureFX. - Dragging a remote file to a remote folder caused an erroneous "Change directory operation failed" error followed by a crash. Changes in SecureFX 2.0 (Beta 2) -- January, 3 2002 --------------------------------------------------- Bug fixes: - A crash occurred when attempting to transfer a file using SFTP, if the destination drive had no available space. - UNC path parsing did not work under Windows 2000 and Windows XP. - GPF occurred when duplicate URLs were specified as source transfer items on the command line. - The most recently used session list was not being updated after attempting to connect to a session. Changes in SecureFX 2.0 (Beta 1) -- December 19, 2001 ----------------------------------------------------- New features: - Automated transfers via command line. - Added the ability to send logging output to a file. - SSH2: Added smart card (X.509 certificate) support for public- key authentication. - SSH2: Added keyboard-interactive authentication. - SSH2: Added support to view, import, export, and delete host keys. - SSH2: Added support for Diffie-Hellman Group Exchange. - SSH2: OpenSSH public/private key file support. - SFTP: ASCII translations for transfers. Bug fixes: - Failed to create the default configuration folder on the first-time startup under Windows XP. - If a refresh operation was in progress when a file operation completed, a second refresh operation ocurred, which caused a memory leak. - Dragging & dropping a file onto a filename in the root folder of a VMS server caused SecureFX to crash. This may have also caused a file to be dropped into the parent folder of the intended folder if the filename was not at the root. - Specifying an invalid session path on the command line caused SecureFX to crash. - SecureFX was not encrypting SFTP passwords that were stored in the database. - Quick Synchronize operations using a relative path for the remote did not work correctly. - Users were prevented from browsing to drive roots when connecting to an SSH Communications 2.4.0 Windows NT server. Changes: - The command-line option now accepts /s as well as /S for specifying a session. - Added ALTt+C and ALT+Q accelerators for the "File/Connect" and "File/Quick Connect" menu items, respectively. - Improved user interface to be like SecureCRT's interface. - Changed "SSH Login" to "Logon" in the "SFTP" and "Quick Connect" dialogs.