Hello! I have Confluence on my server ver. 6.8.
It was hacked somehow and somebody uses it to spam and flood from my server.
How is it possible? I have only atlassian (+nginx) and postgres on the server.
The malware is running as "confluence" user. They changed the crontab and run scripts from pastebin.com.
Hey there,
I agree with your diagnosis that you've been infected specifically with kerberods malware as linked in the other thread, based on the pastebin script that it pulled.
As described in the linked thread that you read, there's a two-step process needed to get this resolved:
Let me know if you have any questions about the upgrade!
Daniel | Atlassian Support
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
In syslog I see:
syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 dbus[1064]: [system] Activating via systemd: service name='org.freedesktop.PolicyKit1' unit='polkitd.service'
syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 systemd[1]: Starting Authenticate and Authorize Users to Run Privileged Tasks...
syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 polkitd[13831]: started daemon version 0.105 using authority implementation `local' version `0.105'
syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 dbus[1064]: [system] Successfully activated service 'org.freedesktop.PolicyKit1'
syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 systemd[1]: Started Authenticate and Authorize Users to Run Privileged Tasks.
syslog.3.gz:Apr 12 14:10:23 vm-wiki-01 crontab[13958]: (confluence) REPLACE (confluence)
So I tried to disable polkitd.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.