DataPacket
New Pleskian
Username:
TITLE
Event 'cp_user_login_failed'
PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE
Plesk Obsidian 18.0.68 Update #1 - Ubuntu 22.04.5 LTS
PROBLEM DESCRIPTION
When Plesk is targeted by a brute-force attack, the "cp_user_login_failed" events are processed by the task manager. With 10,000+ failed login attempts, this significantly amplifies the attack's impact, causing the task-manager process to spike to 100% CPU usage and severely delaying the processing of these events.
STEPS TO REPRODUCE
A brute-force attack on Plesk with 10,000+ login attempts can cause plesk-task-manager to experience extremely high CPU usage and delays, significantly impacting server performance.
ACTUAL RESULT
A brute-force attack on Plesk with 10,000+ login attempts can cause plesk-task-manager to hit 100% CPU usage, leading to a severe backlog of tasks that could take "days" to process.
EXPECTED RESULT
No additional CPU usage, ensuring stable performance.
ANY ADDITIONAL INFORMATION
Not really a bug, but needs optimization.
YOUR EXPECTATIONS FROM PLESK SERVICE TEAM
Help with sorting out
TITLE
Event 'cp_user_login_failed'
PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE
Plesk Obsidian 18.0.68 Update #1 - Ubuntu 22.04.5 LTS
PROBLEM DESCRIPTION
When Plesk is targeted by a brute-force attack, the "cp_user_login_failed" events are processed by the task manager. With 10,000+ failed login attempts, this significantly amplifies the attack's impact, causing the task-manager process to spike to 100% CPU usage and severely delaying the processing of these events.
STEPS TO REPRODUCE
A brute-force attack on Plesk with 10,000+ login attempts can cause plesk-task-manager to experience extremely high CPU usage and delays, significantly impacting server performance.
ACTUAL RESULT
A brute-force attack on Plesk with 10,000+ login attempts can cause plesk-task-manager to hit 100% CPU usage, leading to a severe backlog of tasks that could take "days" to process.
EXPECTED RESULT
No additional CPU usage, ensuring stable performance.
ANY ADDITIONAL INFORMATION
Not really a bug, but needs optimization.
YOUR EXPECTATIONS FROM PLESK SERVICE TEAM
Help with sorting out