yup.
regular encryption is not really an encryption but rather text cypher.
but once application level password is enabled you might as well try to do social engeneering becuase it's virtually impossible to "crack" such password.
which makes me wonder if this
Dvdman@l33tsecurity.com of L33tsecurity 2003 even bothered to contact Bigstar about this, or use FlashFXP to the full extent, as it is customary when finding and reporting vulnerabilities.
plus he didn't "discover" this. password decrypters for flashfxp existed way back in v1.2 days