Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

JIRA is under attack, requesting assistance

Andrew
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
June 26, 2023

 Version: Atlassian Jira Project Management Software (v8.20.3)

Server alarm log: Network traffic content ->GET plugins/servlet/gadgets/makeRequest?url=http:/47.92.118.252:8080@dutyzu.s0xcn HTTP/1.1 Host:47.92.118.252:8080 User-Agent: Mozila/5.0 (Windows NT 10.0: Win64; x64) AppleWebkit/537.36 (KHTML, like Gecko)Chrome/66.6.2333.33 Safari/537.36 AliyunTaiShiGanZhi https://www.aliyun.com/product/sas Accept-Encoding: gzip.deflate Accept: / Connection: keep-alive X-Atlassian-Token: no-check Accept-Language: zh-CN,zh;g=0.8

 

Please note that the JIRA/JSM software is deployed independently on our server, and we have a valid license for it. Catch(06-26-20-26-35).jpg

1 answer

0 votes
Nic Brough -Adaptavist-
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
June 26, 2023

Welcome to the Atlassian Community!

I can't run an image through a translator, so I have no idea what the details of this attack might be, even whether it's a hijack, tunnelling, or denial-of-service attack.

But a DNSlog attack is not something that an application should be dealing with.  You need to fix your network, such that it blocks or at least throttles DNSlog attacks.  The Atlassian community can't help you with this really, it's not an Atlassian problem.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events