• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Issue Password Strength Policy - Strange behavior

Almaz

New Pleskian
Hello everyone,

I have a strange behavior on a Plesk server I manage, I set the Password Strength Policy to high, but sometimes email addresses get their passwords broken and send spam.
When I take a look at the passwords, sometimes users seems to be able to put a weak password.

For exemple :

| [email protected] | | saccoan |
| [email protected] | | CONTACT |
| [email protected] | | PERINE |

How it is possible ? I tried to put passwords like that, the system prevent me to do it.

These are, of course, passwords configured after the security policy change. All weak passwords were changed right after the policy change.

The server infos :

OS ‪Debian 8.11‬
Produit Plesk Onyx
Version 17.8.11 Mise à jour n° 88, dernière mise à jour le 5 Nov 2020 18:59

If someone has the slightest idea, that would be great ! :)

Thanks,

Arnaud
 

Attachments

  • Capture d’écran 2021-07-30 à 19.19.58.png
    Capture d’écran 2021-07-30 à 19.19.58.png
    1.3 MB · Views: 11
How did you change all the weak passwords? Maybe that process didn't or doesn't use the security policy correctly?

Maybe you can try performing that process again and try to set a weak password?
 
Back
Top