• Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Login plesk 'admin' lock attack possible ?

B

BoXie

Guest
Hi,

Is this possible ? If yes ... please fix this a.s.a.p. !!!!

Situation:
-------------
I look for a Plesk hoster find his login-screen and start a login procedure for 'admin' every 20 seconds. After X-times .. admin account will be locked for about 30 minutes.

After that I go back and lock the admin account again (by logging in 3 times with wrong credentials.).

This way, Plesk admin's cannot access their Plesk anymore (at least .. not that simple).

Can Plesk hosters be harassed like this in combination with a simple script ?

SO: is admin-locking IP-sensitive or not ?

If not --> serious problem.
 
You can lock down admin logins to use a blacklist whitelist if you go to SERVER->ACCESS. If someone were to try this, you could simply blacklist their IP, or whitelist your own range, and block everyone else. The server admin can always unlock a session by removing it from the DB as well.

Just like any DoS attack, mitigation at the network level is key.
 
Back
Top