Is there any patch available to prevent this attack? Any suggestion or recommended method?
"https://searchsecurity.techtarget.com/news/2525
Yes, see the announcement at https://community.atlassian.com/t5/Confluence-articles/Security-Advisory-for-Confluence-Server-and-Data-Center-August/ba-p/1787026
Yes, there's already a workaround for affected versions listed on this link.
Thanks for the prompt response.
Hi,
Do we run the mitigation script first, then patch? Or do we only patch? I have my server's network turned off at the moment, and patching wants to do a yum update, so I'm not sure if the patch will work.
Thanks!
David
Running the workaround/mitigation script is recommended which will temporarily mitigate the issue until you can upgrade to a version that fixes this permanently.
Hi @software_tspl_tallysolutions_com
are you already affected by malicious code running on your server placed there by a hacker?
I am asking because while patching the vulnerable Confluence installation alongside with removing the malicious crypto miner is the correct measure in first place you would need to assess if the server is compromised in a way it needs probably to be restored from backup.
Basically if a machine got hacked it should not be trusted anymore. In case this applies, please do a thorough check of the environment, too. The malware seen in that cases is reported to "jump" to other hosts, too.
Regards,Daniel
Great, thanks for the update.
I did just that - restored from backup, ran the mitigation script, turned on networking, then applied the 7.13.0 patch. Everything is working great now and we're not seeing any evidence of infection (on any of our servers).
good to know, David!
It looks like you're new here. Sign in or register to get started.