Confluence was hacked

Администратор April 15, 2019

Hello! I have Confluence on my server ver. 6.8.

It was hacked somehow and somebody uses it to spam and flood from my server.

How is it possible? I have only atlassian (+nginx) and postgres on the server.

The malware is running as "confluence" user. They changed the crontab and run scripts from pastebin.com.

Снимок экрана 2019-04-15 в 18.09.39.png

3 answers

1 accepted

3 votes
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 15, 2019

Hey there,

I agree with your diagnosis that you've been infected specifically with kerberods malware as linked in the other thread, based on the pastebin script that it pulled.

As described in the linked thread that you read, there's a two-step process needed to get this resolved:

  1. Upgrade Confluence to a version unaffected by CVE-2019-3396 Widget Connector vulnerability from March 20th (see Confluence Security Advisory - 2019-03-20)
  2. Clean up the malware infection - most folks have had success with the LSD malware cleanup tool.

Let me know if you have any questions about the upgrade!
Daniel | Atlassian Support

0 votes
Администратор April 15, 2019

In syslog I see:

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 dbus[1064]: [system] Activating via systemd: service name='org.freedesktop.PolicyKit1' unit='polkitd.service'

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 systemd[1]: Starting Authenticate and Authorize Users to Run Privileged Tasks...

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 polkitd[13831]: started daemon version 0.105 using authority implementation `local' version `0.105'

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 dbus[1064]: [system] Successfully activated service 'org.freedesktop.PolicyKit1'

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 systemd[1]: Started Authenticate and Authorize Users to Run Privileged Tasks.

syslog.3.gz:Apr 12 14:10:23 vm-wiki-01 crontab[13958]: (confluence) REPLACE (confluence)

So I tried to disable polkitd.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events