• The APS Catalog has been deprecated and removed from all Plesk Obsidian versions.
    Applications already installed from the APS Catalog will continue working. However, Plesk will no longer provide support for APS applications.
  • Please be aware: with the Plesk Obsidian 18.0.78 release, the support for the ngx_pagespeed.so module will be deprecated and removed from the sw-nginx package.

Issue Password Strength Policy - Strange behavior

Almaz

New Pleskian
Hello everyone,

I have a strange behavior on a Plesk server I manage, I set the Password Strength Policy to high, but sometimes email addresses get their passwords broken and send spam.
When I take a look at the passwords, sometimes users seems to be able to put a weak password.

For exemple :

| [email protected] | | saccoan |
| [email protected] | | CONTACT |
| [email protected] | | PERINE |

How it is possible ? I tried to put passwords like that, the system prevent me to do it.

These are, of course, passwords configured after the security policy change. All weak passwords were changed right after the policy change.

The server infos :

OS ‪Debian 8.11‬
Produit Plesk Onyx
Version 17.8.11 Mise à jour n° 88, dernière mise à jour le 5 Nov 2020 18:59

If someone has the slightest idea, that would be great ! :)

Thanks,

Arnaud
 

Attachments

  • Capture d’écran 2021-07-30 à 19.19.58.png
    Capture d’écran 2021-07-30 à 19.19.58.png
    1.3 MB · Views: 11
How did you change all the weak passwords? Maybe that process didn't or doesn't use the security policy correctly?

Maybe you can try performing that process again and try to set a weak password?
 
Back
Top