Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

内网最好不要检测弱密码 #860

Closed
2 tasks done
canoziia opened this issue Sep 14, 2023 · 6 comments
Closed
2 tasks done

内网最好不要检测弱密码 #860

canoziia opened this issue Sep 14, 2023 · 6 comments
Labels
enhancement New feature or request

Comments

@canoziia
Copy link

canoziia commented Sep 14, 2023

功能描述

感觉内网检测弱密码不是很必要,而且现在的情况是禁止内网时,可以不进行验证,但是不可以弱密码,有点怪。或者加一个跳过检测弱密码的选项,并且给个警告?

解决的问题

内网设置简单密码时不允许保存

附加信息

No response

检查清单

  • 我已搜索同类问题,并确保没有我要提交的功能
  • 我已使用最新版本,并确保该功能仍未在最新版本中实现
@canoziia canoziia added the enhancement New feature or request label Sep 14, 2023
@jeessy2
Copy link
Owner

jeessy2 commented Sep 15, 2023

内网也有可能被扫。。你想被扫?

@canoziia
Copy link
Author

内网也有可能被扫。。你想被扫?

如果别人已经在内网扫了,那密码还有意义吗

@jeessy2
Copy link
Owner

jeessy2 commented Sep 15, 2023

有意义,防止被爆破

@jeessy2
Copy link
Owner

jeessy2 commented Sep 15, 2023

亲身经历,其它项目存在漏洞,被上传木马,内网被攻破后,会继续扫内网其它弱口令机器

@canoziia
Copy link
Author

大概明白了,但是现在内网好像还可以允许空账号密码?如果是这样的话是不是应该考虑内网也必须设置密码

@jeessy2
Copy link
Owner

jeessy2 commented Sep 15, 2023

允许,如果是进行“修改密码”、“设置通过命令获取”,会强制要求启动时间在五分钟内

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants