Hello, my confluence server was affected by the ramsonware commented. Is there any guide o recomendations to recover an instance infected?
I have a 3 months old backup. If i could recover some files i could start the confluence again? without do a full reinstall ?
It is neccesary to do a full reinstall?, i have to do with a clean linux installation? or just confluence ?
can i use the actual database?
thanks in advance.
There are some websites out there which claim to be able to recover the data. I haven't used them personally, but you could potentially look into them. The ideal scenario would be to restore from the last good state that you have. I understand that a backup from 3 months ago is not ideal, but if you cannot decrypt the file, there may not be another choice.
Have you checked to see if your DB is intact? I believe when they attack they actually overwrite your DB as well..
@Kian Stack Mumo Systems , i checked the database and it seems is working, i could see the information in some tables without any strange.
Do you remember some site?, i will try to install again confluence, but keeping the database and using my old data folder backup.
Thank you.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I would google it. Again, I don't actually know whether or not they can decrypt them, it was just something that came up when I was researching the bug.
If your database is still functional that is good news, but I seem to recall that they restore a blank backup which effectively overwrites your site and database.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.