• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Issue Password Strength Policy - Strange behavior

Almaz

New Pleskian
Hello everyone,

I have a strange behavior on a Plesk server I manage, I set the Password Strength Policy to high, but sometimes email addresses get their passwords broken and send spam.
When I take a look at the passwords, sometimes users seems to be able to put a weak password.

For exemple :

| [email protected] | | saccoan |
| [email protected] | | CONTACT |
| [email protected] | | PERINE |

How it is possible ? I tried to put passwords like that, the system prevent me to do it.

These are, of course, passwords configured after the security policy change. All weak passwords were changed right after the policy change.

The server infos :

OS ‪Debian 8.11‬
Produit Plesk Onyx
Version 17.8.11 Mise à jour n° 88, dernière mise à jour le 5 Nov 2020 18:59

If someone has the slightest idea, that would be great ! :)

Thanks,

Arnaud
 

Attachments

  • Capture d’écran 2021-07-30 à 19.19.58.png
    Capture d’écran 2021-07-30 à 19.19.58.png
    1.3 MB · Views: 11
How did you change all the weak passwords? Maybe that process didn't or doesn't use the security policy correctly?

Maybe you can try performing that process again and try to set a weak password?
 
Back
Top