First of all, the server I run Confluence has no enough disk for the weekly backup job for the Confluence website and I can not access the Confluence website from my web browser.
Then, I run stop-confluence.sh which reports that kill the process failed. I run 'kill -9 XXXX' on the confluence process I can see in the 'top' command shows.
Then, I start the confluence server by running 'start-confluence.sh' as root. But I still cannot access the Confluence website and I found the zombie process of user "confluence" causes High CPU usage:
and I CAN NOT kill the process any more, even I reboot the system.
I see in the atlassian-confluence.log as following:
2019-04-19 13:30:29,421 WARN [synchrony-interop-executor:thread-2] [plugins.synchrony.bootstrap.DefaultSynchronyProxyMonitor] pollHealthcheck Could not ping the synchrony-proxy [http://127.0.0.1:8090/synchrony-proxy/healthcheck]: {}
-- url: /longrunningtaskxml.action | referer: http://****:8090/admin/restore-local-file.action | traceId: 5eb0806c7e6e9c96 | userName: *** | action: longrunningtaskxml
The Confluence Version I used is 6.9.1-x64
Hey Vujacic, welcome to the Community.
As Bastian linked, it looks like your instance has been attacked due to a security vulnerability. I've written up some general first steps for detection (you've identified a malicious process) on this article. For your case, I would recommend looking at the crontab next (instructions in the article) to stop the process from re-launching itself.
We are happy to help on this question if you continue to have issues after going through the article. Please let us know!
Thanks,
Daniel | Atlassian Support
Thanks for your help.
I see the virus in '/var/spool/cron/confluence' and I have upgraded Confluence already.
Thx!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @VujacicSun ,
There is a vulnerability in confluence that is attached a lot this month and it seems that you have been hit by that.
Here is the advisory regarding this https://confluence.atlassian.com/doc/confluence-security-advisory-2019-04-10-968660855.html
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks for your help.
It's exactly the problem as you attached and I have upgraded Confluence from 6.9.1 to 6.12.4. It seems back to normal.
Thx!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.