• We value your experience with Plesk during 2025
    Plesk strives to perform even better in 2026. To help us improve further, please answer a few questions about your experience with Plesk Obsidian 2025.
    Please take this short survey:

    https://survey.webpros.com/

Email password not encrypted.

R

Resamarr

Guest
Hello,
I just found out that the email password are not encrypted and can be accessible using the following command:

mysql -uadmin -p`cat /etc/psa/.psa.shadow` psa

use psa;

SELECT CONCAT_WS('@',mail.mail_name,domains.name),accounts.password
FROM domains,mail,accounts WHERE domains.id=mail.dom_id AND accounts.id=mail.account_id ORDER BY domains.name ASC,mail.mail_name ASC;

How can I encrypt them because it's a breach in security in order to ensure my customers.

Thank you in advance.
 
Check output of '/usr/local/psa/bin/mail --help' command about -passwd_type
 
Back
Top