Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Hello! I have Confluence on my server ver. 6.8.

It was hacked somehow and somebody uses it to spam and flood from my server.

How is it possible? I have only atlassian (+nginx) and postgres on the server.

The malware is running as "confluence" user. They changed the crontab and run scripts from pastebin.com.

Снимок экрана 2019-04-15 в 18.09.39.png

3 answers

1 accepted

3 votes
Daniel Eads Atlassian Team Apr 15, 2019

Hey there,

I agree with your diagnosis that you've been infected specifically with kerberods malware as linked in the other thread, based on the pastebin script that it pulled.

As described in the linked thread that you read, there's a two-step process needed to get this resolved:

  1. Upgrade Confluence to a version unaffected by CVE-2019-3396 Widget Connector vulnerability from March 20th (see Confluence Security Advisory - 2019-03-20)
  2. Clean up the malware infection - most folks have had success with the LSD malware cleanup tool.

Let me know if you have any questions about the upgrade!
Daniel | Atlassian Support

In syslog I see:

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 dbus[1064]: [system] Activating via systemd: service name='org.freedesktop.PolicyKit1' unit='polkitd.service'

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 systemd[1]: Starting Authenticate and Authorize Users to Run Privileged Tasks...

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 polkitd[13831]: started daemon version 0.105 using authority implementation `local' version `0.105'

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 dbus[1064]: [system] Successfully activated service 'org.freedesktop.PolicyKit1'

syslog.3.gz:Apr 12 14:10:21 vm-wiki-01 systemd[1]: Started Authenticate and Authorize Users to Run Privileged Tasks.

syslog.3.gz:Apr 12 14:10:23 vm-wiki-01 crontab[13958]: (confluence) REPLACE (confluence)

So I tried to disable polkitd.

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Confluence

🏑 Atlympic Event: Confluence

Hello Community!  Quick disclaimer: We are running a contest on Community (The Atlympics!) from July 23rd - August 8th of 2021. If you are interested in participating in this contest (prizes! ...

517 views 18 17
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you