Is there any patch available to prevent this attack? Any suggestion or recommended method?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks for the prompt response.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @software_tspl_tallysolutions_com
are you already affected by malicious code running on your server placed there by a hacker?
I am asking because while patching the vulnerable Confluence installation alongside with removing the malicious crypto miner is the correct measure in first place you would need to assess if the server is compromised in a way it needs probably to be restored from backup.
Basically if a machine got hacked it should not be trusted anymore. In case this applies, please do a thorough check of the environment, too. The malware seen in that cases is reported to "jump" to other hosts, too.
Regards,
Daniel
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi,
Do we run the mitigation script first, then patch? Or do we only patch? I have my server's network turned off at the moment, and patching wants to do a yum update, so I'm not sure if the patch will work.
Thanks!
David
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Running the workaround/mitigation script is recommended which will temporarily mitigate the issue until you can upgrade to a version that fixes this permanently.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Great, thanks for the update.
I did just that - restored from backup, ran the mitigation script, turned on networking, then applied the 7.13.0 patch. Everything is working great now and we're not seeing any evidence of infection (on any of our servers).
David
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.