Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

C3RB3R how to recover instance

Diego Villagra January 23, 2024

Hello, my confluence server was affected by the ramsonware commented. Is there any guide o recomendations to recover an instance infected?

I have a 3 months old backup. If i could recover some files i could start the confluence again? without do a full reinstall ? 

It is neccesary to do a full reinstall?, i have to do with a clean linux installation? or just confluence ? 

can i use the actual database?

 

thanks in advance.

 

1 answer

0 votes
Kian Stack Mumo Systems
Community Champion
January 23, 2024

@Diego Villagra

 

There are some websites out there which claim to be able to recover the data. I haven't used them personally, but you could potentially look into them. The ideal scenario would be to restore from the last good state that you have. I understand that a backup from 3 months ago is not ideal, but if you cannot decrypt the file, there may not be another choice.

 

Have you checked to see if your DB is intact? I believe when they attack they actually overwrite your DB as well..

Diego Villagra January 23, 2024

@Kian Stack Mumo Systems , i checked the database and it seems is working, i could see the information in some tables without any strange.

Do you remember some site?, i will try to install again confluence, but keeping the database and using my old data folder backup.

Thank you.

Kian Stack Mumo Systems
Community Champion
January 23, 2024

I would google it. Again, I don't actually know whether or not they can decrypt them, it was just something that came up when I was researching the bug.

 

If your database is still functional that is good news, but I seem to recall that they restore a blank backup which effectively overwrites your site and database. 

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
VERSION
8.5.3
TAGS
AUG Leaders

Atlassian Community Events