F5 Sites
  • F5.com
  • LearnF5
  • NGINX
  • MyF5
  • Partner Central
Contact
  • Under Attack?
  • F5 Support
  • DevCentral Support
  • F5 Sales
  • NGINX Sales
  • F5 Professional Services
Brand LogoSkip to content
Forums
CrowdSRC
Articles
Groups
EventsSuggestionsHow Do I...?
RegisterSign In
  1. DevCentral
  2. CrowdSRC
  3. CodeShare

Pwned Passwords Check

Problem this snippet solves: This snippet makes it possible to use Troy Hunt’s ‘Pwned Passwords’ API. By using this API one can check if the password being used was exposed in earlier data breaches....
Updated Jun 06, 2023
Version 2.0
api
application delivery
BIG-IP Access Policy Manager (APM)
devops
irule
password
pwned
Niels_van_Sluis's avatar
Niels_van_Sluis
Icon for MVP rankMVP
Joined May 16, 2019
View Profile
EricBrokeIt_245's avatar
EricBrokeIt_245
Icon for Nimbostratus rankNimbostratus
Sep 10, 2018

All this is 12.x mind you.

 

Yeah, it doesn't seem to be logging anything in the LTM related to it. Added a log item in the iRule just to see if it was hitting and got nothing, even put in something to show that a password was at least hitting the VA-Get Password. Still nothing.

 

 

So went into APM and made a lot setting to debug everything with everything on. I see the IE-HIBP hit and fallback. But it happens on every password, used a test users with a 23 character randomly generated password with all the number, special character, capitals, etc, options. it hits fallback every time.

 

 

ABOUT DEVCENTRAL

DevCentral NewsTechnical ForumTechnical ArticlesTechnical CrowdSRCCommunity GuidelinesDevCentral EULAGet a Developer Lab LicenseBecome a DevCentral MVP

RESOURCES

Product DocumentationWhite PapersGlossaryCustomer StoriesWebinarsFree Online CoursesF5 CertificationLearnF5 Training

SUPPORT

Manage SubscriptionsProfessional ServicesProfessional ServicesCreate a Service RequestSoftware DownloadsSupport Portal

PARTNERS

Find a Reseller PartnerTechnology AlliancesBecome an F5 PartnerLogin to Partner Central

F5 logo©2024 F5, Inc. All rights reserved.
TrademarksPoliciesPrivacyCalifornia PrivacyDo Not Sell My Personal Information