Hello, my confluence server was affected by the ramsonware commented. Is there any guide o recomendations to recover an instance infected?
I have a 3 months old backup. If i could recover some files i could start the confluence again? without do a full reinstall ?
It is neccesary to do a full reinstall?, i have to do with a clean linux installation? or just confluence ?
can i use the actual database?
thanks in advance.
There are some websites out there which claim to be able to recover the data. I haven't used them personally, but you could potentially look into them. The ideal scenario would be to restore from the last good state that you have. I understand that a backup from 3 months ago is not ideal, but if you cannot decrypt the file, there may not be another choice.
Have you checked to see if your DB is intact? I believe when they attack they actually overwrite your DB as well..
@Kian Stack Mumo Systems , i checked the database and it seems is working, i could see the information in some tables without any strange.
Do you remember some site?, i will try to install again confluence, but keeping the database and using my old data folder backup.
Thank you.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I would google it. Again, I don't actually know whether or not they can decrypt them, it was just something that came up when I was researching the bug.
If your database is still functional that is good news, but I seem to recall that they restore a blank backup which effectively overwrites your site and database.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.