Repository navigation
ProtoHydra 1.5
Language / Sprache: 🇬🇧 English · 🇩🇪 Deutsch
Multi-protocol file server for system administrators – TFTP, FTP, FTPS, SFTP, SCP, HTTP and HTTPS from a single folder, portable and installation-free.
English
Download
Download and run ProtoHydra.exe – self-contained (x64), no .NET required.
What's new in 1.5
- Optional authentication with defined users – the new Configure Authentication dialog (header link) switches from the default Accept-Any policy to defined users with passwords. Multiple users, add/remove/change password, applied live without restarting the listeners.
- Argon2id password hashing – passwords are persisted exclusively as Argon2id hashes (PHC format, RFC 9106 parameters), never in plaintext; verification is constant-time. A corrupt settings file fails closed instead of silently reopening the server.
- Enforced across protocols – FTP/FTPS (login check), SFTP/SCP (SSH password authentication; public-key is rejected so clients fall back to password) and HTTP/HTTPS (Basic auth with 401 challenge). Rejected logins appear in the live log with source IP.
- TFTP note – TFTP has no authentication in the protocol itself and always remains open; the UI states this clearly when defined users are active.
Note
By default ProtoHydra uses Accept-Any authentication and is intended for maintenance/device networks, not for permanent, publicly reachable operation. Over plain HTTP/FTP credentials travel unencrypted – prefer HTTPS, FTPS or SFTP for authenticated access.
Licenses
ProtoHydra is licensed under the MIT License. All bundled open-source components and their licenses (MIT, Apache-2.0, MS-PL and others – new in 1.5: Konscious.Security.Cryptography, MIT) are documented in the accompanying THIRD-PARTY-NOTICES.txt and are also viewable in the app under "Lizenzen & Hinweise" (top right).
Feedback & support
If ProtoHydra is useful to you, a ⭐ on GitHub would make my day! Found a bug or missing something? Please open an issue: https://github.com/ThatIsCraZy/ProtoHydra/issues
Deutsch
Download
ProtoHydra.exe herunterladen und starten – self-contained (x64), kein .NET erforderlich.
Neu in 1.5
- Optionale Authentifizierung mit definierten Benutzern – der neue Configure Authentication-Dialog (Link im Kopfbereich) schaltet von der Standard-Accept-Any-Policy auf definierte User mit Passwörtern um. Mehrere Benutzer, Anlegen/Entfernen/Passwort ändern, Umschaltung greift live ohne Neustart der Listener.
- Argon2id-Passwort-Hashing – Passwörter werden ausschließlich als Argon2id-Hashes gespeichert (PHC-Format, RFC-9106-Parameter), nie im Klartext; die Prüfung ist zeitkonstant. Eine defekte Einstellungsdatei schließt den Server (fail-closed), statt ihn unbemerkt zu öffnen.
- Durchgesetzt über alle Protokolle – FTP/FTPS (Login-Prüfung), SFTP/SCP (SSH-Passwort-Authentifizierung; Public-Key wird abgelehnt, Clients fallen auf Passwort zurück) und HTTP/HTTPS (Basic Auth mit 401-Challenge). Abgelehnte Logins erscheinen im Live-Log inkl. Quell-IP.
- TFTP-Hinweis – TFTP kennt protokollbedingt keine Authentifizierung und bleibt immer offen; die UI weist bei aktiven definierten Usern deutlich darauf hin.
Hinweis
Standardmäßig nutzt ProtoHydra Accept-Any-Authentifizierung und ist für Wartungs-/Geräte-Netze gedacht, nicht für den öffentlich erreichbaren Dauerbetrieb. Über unverschlüsseltes HTTP/FTP reisen Credentials im Klartext – für authentifizierte Zugriffe HTTPS, FTPS oder SFTP bevorzugen.
Lizenzen
ProtoHydra steht unter der MIT-Lizenz. Alle gebündelten Open-Source-Komponenten und ihre Lizenzen (MIT, Apache-2.0, MS-PL u. a. – neu in 1.5: Konscious.Security.Cryptography, MIT) sind in der beiliegenden THIRD-PARTY-NOTICES.txt dokumentiert und zusätzlich in der App unter „Lizenzen & Hinweise" (oben rechts) einsehbar.
Feedback & Support
Wenn dir ProtoHydra weiterhilft, freue ich mich riesig über einen ⭐ auf GitHub! Fehler gefunden oder fehlt dir etwas? Bitte melde es als Issue: https://github.com/ThatIsCraZy/ProtoHydra/issues