Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

131–140 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#131

My employer was bit by this on Wednesday. Thankfully we had Crowdstrike on it which blocked any real damage. But it definitely moved our cloud migration from “later this year” to “later this month”. Also, not having confluence for a day exposed just how reliant we were on it for day-to-day activities.

Got hit too. We are moving to cloud in 3 days!

Tip: adding noexec to /tmp helped.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#132

Earlier quoted context omitted.

I only got the 'update' from last Saturday, by then it was too late already. Their original advisory was from the 25th, they should have mailed me back then.

If you got the one from Sep 4, you definitely should have gotten the one from Aug 25. This is unrelated to any mailing-list change, since both were sent from/to the 10991049.xt.local mailing list. Search for the header entry `List-ID: ` in your Sep 4 email. If it came from that list, the one from Aug 25 will very likely have been lost during transit. I use their products in the 10-user license program since 2016 and…

I'm listed as the technical contact and have been for 5+ years and also get the regular mails to 'verify contact details'. I did not get the Aug 25 email. I did get the Sep 4 mail from that list ID.

Once I noticed I did not get an email, on Sep 3, I checked some checkboxes at https://my.atlassian.com/email But that page also says tech contacts should always receive an email regardless of settings. I have received other security announcements in the past.

Office 365 can't find any emails from Atlassian on Aug 25 when searching using the Message trace tool (which also includes any spam mails, deleted mails, et cetera), so I would suggest Atlassian fix their mailing list.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#133

Earlier quoted context omitted.

your CS person would likely have reached out if they’re anything like Amazon, Microsoft, Salesforce, etc. The only companies that are like those companies are those companies. In most companies, the CS people don't know what anything in that sort of alert means and will discard it thinking that it's a spam or phishing attempt. The problem is not that he doesn't work for a megacorp. The problem is that Atlassian screw…

Where did they screw up? How do you know that the mail wasn't lost/filtered after being sent?

If O365 can't find the email and the O365 message tracing does not show anything, it seems likely that the mail was not actually delivered by Atlassian. If O365 looses mails and these mails do not show up in message tracing either (i.e., not classified as spam), we would probably have heard about that by now.

Also, regardless of whether or not I received the mail, the initial mail stated that only authorized users could exploit this. So Atlassian did not inform any of their users fully until Sep 4, whereas they were well aware on Aug 26 that the vulnerability was exploitable by anyone.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#134

Earlier quoted context omitted.

Where did they screw up? How do you know that the mail wasn't lost/filtered after being sent?

If O365 can't find the email and the O365 message tracing does not show anything, it seems likely that the mail was not actually delivered by Atlassian. If O365 looses mails and these mails do not show up in message tracing either (i.e., not classified as spam), we would probably have heard about that by now. Also, regardless of whether or not I received the mail, the initial mail stated that only authorized users co…

> If O365 looses mails and these mails do not show up in message tracing either (i.e., not classified as spam), we would probably have heard about that by now.

Internet email has never been considered a highly-reliable messaging system; its quite possible an infrequent data loss in a mail server would get misattributed to a failure outside.

Heck, even ignoring the unreliability of email generally, in fact, your assumption that it must not occur because you haven't previously heard about it demonstrates how that might happen.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#135
post #4

I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.

I have no idea why you're being downvoted - this is true. Atlassian produce some of the worst tech on the planet. Trying to administer this crap is horrible. And don't get me started on how many project managers spend all day staring at Jira tickets instead of actually talking to their teams. Management-by-Jira is a disease, a symptom of bad organisational culture.

I'd rather get a fully-formed Jira ticket, than a terse three-word titled empty ticket, that the PM will explain in a 9AM Zoom meeting. Just me though.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#136

Earlier quoted context omitted.

Atlassian products are vast, integrated, and support all the crazy draconian processes that every insane project manager wants to implement. You can't easily dump Jira if you are using Jira, confluence, bitbucket, and whatever their CI/CD product is called (bamboo?)

Clubhouse (soon to be renamed Shortcut) covers the first two. Github covers the latter two. It's easier to switch than ever.

No it's not easy to switch. Engineeting Organisations have invested a lot in the Jira eco system, that includes custom workflows that are understood only by a few to be able to alter them, users are productive right now with jira and nobody wants them less productive even just for a while learning another task manager. Here again the integration effort to migrate would scare any leader who would be blame for the impact on so many teams deliverables. The effort is enormous and error prone to take all the data in there, move it elsewhere, rebuild the workflow and integration configuration, while keeping track of lack of feature parity to write down an explanation before everyone complains and pre empting their request to at least provide a work around what they used to be able to do with 3 clicks. Confluence slips right in because it integrates very well with jira. Just embed a confluence page into a task, and just mention a jira task within a confluence page and you get a seamless experience. Yes we could use another wiki , and a good one as confluence is a calamity. But convenience is what organisations are after. Perfect is the enemy of the good they will say. I don't have a love for atlassian products, but they tend to do their job very well compared to the majority of the competition. You will always find one product that compares, or even is superior but overall, their product works. So here we are.

If they get plagued by further security vulnerabilities then companies handling sensitive data will concede to migrate, but it won't be simple by any means.

If you believe changing people's habits is easier than ever, it's rather the opposite. Workers are less and less inclined to learn any other way . The alternative has to be order of magnitude better than what they are using, otherwise they will resist the change. The fact is atlassian provide good to great products overall.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#137
post #94
post #36

Earlier quoted context omitted.

I personally do not categorize them to equivalent to Confluence, Sharepoint, Notion, Quip, ... but if you do, yeah there are few wiki software which are available on premise.

What can confluence do what XWiki cannot? But i understand that you try to promote your cloud offering ;)

I'm not trying to promote my cloud offering. I would like to be able to offer self hosting, but we still haven't found a way to do it. This is too much hassle for everyone. There is a tradeoff between ease of use of a software and the security process. A collaboration tool which is difficult to update and thus will not evolve quickly is an issue for its adoption and for its benefits.

Well first its interface, if a non technical user can't user the tool that's going to be a big problem. Confluence has not the best interface but still better than Xwiki. The best the interface the better the adoption as a whole in the company. And for knowledge sharing adoption is critical. That's actually why Notion has been such a success recently. Even though their product is average, people want to use it, because they like the interface.

I don't have the time to do a full comparaison of other features, but wiki tools are in usage very different than collaboration tools. Can you have the list of last consulted documents ? Can you embed external documents ? ... Kind of the same things as Slack vs IRC

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#138

Earlier quoted context omitted.

Can't but help to feel that what you describe is a breakdown of both organization and work process. It wasn't atlassian that "came along" - someone penned down an agreement and, from what it sounds, there was a lack of clarity both in regards to current and future principles of work and collaboration. What we can do, as devs, to protect ourselves from the madness you describe is to be explicit about our work processe…

The thing I've found is that Jira has so many fields on its tickets that beg to be filled in, that PMs start filling them in, and before you know it they're all mandatory and must be filled in. And organising that much state in the tickets becomes a full-time job, and so the PM ends up doing that - managing the state of Jira rather than managing the state of the project. The two become synonymous when they're not. Wh…

So basically you are describing an organization of people that don't really understand what they should be doing.

People led by a tool and not the other way around - and you blame the tool?

I hear what you are saying, and I've seen the very symptoms you're describing - I've just stopped chalking it down to the tools.

It's a symptom of something entirely different and much more challenging to deal with than a change in tooling.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#139
post #29
post #6

Earlier quoted context omitted.

Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.

Biased but I'm actually building a competitor (V1 is almost ready) to Confluence for medium to big organizations. But I don't understand your requirement for on-prem. That's clearly not an advantage from the security point of view. Apart from Quip, Sharepoint and Confluence (soon stopped) I'm not sure there is any commercial knowledge base tool that are available on-prem. The only thing that you can hope for, is "bri…

The issue is that to put company data on your server, we need IT security people to sign off on it. That takes years and a lot of budget, just to get that authorization. It also likely comes with restrictions, like not being able to use it for very sensitive company data or government data.

In short, that’s not happening for a wiki.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#140

Earlier quoted context omitted.

If O365 can't find the email and the O365 message tracing does not show anything, it seems likely that the mail was not actually delivered by Atlassian. If O365 looses mails and these mails do not show up in message tracing either (i.e., not classified as spam), we would probably have heard about that by now. Also, regardless of whether or not I received the mail, the initial mail stated that only authorized users co…

> If O365 looses mails and these mails do not show up in message tracing either (i.e., not classified as spam), we would probably have heard about that by now. Internet email has never been considered a highly-reliable messaging system; its quite possible an infrequent data loss in a mail server would get misattributed to a failure outside. Heck, even ignoring the unreliability of email generally, in fact, your assum…

I would beg to differ about email reliability, also see https://datatracker.ietf.org/doc/html/rfc5321#section-6.1 but do agree that everything could get lost for some reason.

But that is not the main point. Even if the email was lost somewhere in Office 365, people were already pointing out to Atlassian that they should really send a follow up on Aug 27:

https://jira.atlassian.com/browse/CONFSERVER-67940?focusedCo...

Post reply on HN