Weak service passwords

Updated at:
Copy as MD

This topic describes how to fix weak service passwords.

Threat description

A weak password on your server can allow hackers to gain unauthorized access, steal data, or disrupt services.

Fixes

If your server uses a common weak password, such as 'admin', 'admin123', 'root', or 'test', change it to a strong password immediately. We recommend that you also change your password regularly. A strong password is long and includes a mix of uppercase letters, lowercase letters, numbers, and special characters.

System Name

Fix

Linux

Use Alibaba Cloud SSH key pairs to log on to Linux instances. For more information, see Log on to a Linux instance using an SSH key pair.

Nacos weak password

In the Nacos console, go to Access Control -> User List. In the Operation column, click the Modify button to change the password for the nacos user.

Redis weak password

In the redis.conf configuration file, set the requirepass parameter to a strong password. Then, save the file and restart the Redis service.

If you need help with these fixes, go to the Security Center console. Then, click "Need Security Help" to contact a technical engineer.