Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Hello! I have Confluence on my server ver. 6.8.

It was hacked somehow and somebody uses it to spam and flood from my server.

How is it possible? I have only atlassian (+nginx) and postgres on the server.

The malware is running as "confluence" user. They changed the crontab and run scripts from pastebin.com.

Снимок экрана 2019-04-15 в 18.09.39.png

3 answers

1 accepted

3 votes
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
Apr 15, 2019

Hey there,

I agree with your diagnosis that you've been infected specifically with kerberods malware as linked in the other thread, based on the pastebin script that it pulled.

As described in the linked thread that you read, there's a two-step process needed to get this resolved:

  1. Upgrade Confluence to a version unaffected by CVE-2019-3396 Widget Connector vulnerability from March 20th (see Confluence Security Advisory - 2019-03-20)
  2. Clean up the malware infection - most folks have had success with the LSD malware cleanup tool.

Let me know if you have any questions about the upgrade!
Daniel | Atlassian Support

In syslog I see:

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 dbus[1064]: [system] Activating via systemd: service name='org.freedesktop.PolicyKit1' unit='polkitd.service'

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 systemd[1]: Starting Authenticate and Authorize Users to Run Privileged Tasks...

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 polkitd[13831]: started daemon version 0.105 using authority implementation `local' version `0.105'

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 dbus[1064]: [system] Successfully activated service 'org.freedesktop.PolicyKit1'

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 systemd[1]: Started Authenticate and Authorize Users to Run Privileged Tasks.

syslog.3.gz:Apr 12 14:10:23 vm-wiki-01 crontab[13958]: (confluence) REPLACE (confluence)

So I tried to disable polkitd.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events