Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

201–210 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#201
post #5

Why are internally hosted instances even available on the public internet?

For those that believe in the zero trust model, don't all apps and services become exposed to the public internet?

All apps authenticate every request thus making lateral movement harder. IP addresses are not authentication. OS's don't control IP traffic in any meaningful way: confused deputies all the way down.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#202

Earlier quoted context omitted.

> The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. Regardless of what one thinks about Atlassian, this is a completely ridiculous bullshit statement, and anyone who works in the world of business software knows it. I don't think there is a company out there that hasn't had c…

You are missing the point entirely. Any sufficiently complicated product will eventually have major CVEs, as you say. Anyone having hosted Atlassians product know that these products are nothing but garbage fires on the inside, as the commenter above said. Both of these statements are true and not mutually exclusive in any way.

However, one does not conclude from the other as is insinuated in the comment.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#203

Why is Confluence so popular anyway? Why not just use any free wiki software?

Because most free wiki software is kind of bland and terrible. Don't get me wrong, they are amazing for what they are but they don't scream "professional".

But actually that's not the key point. Nobody buys just Confluence. That would be silly. A bland and terrible (but free) wiki software is definitely better than Confluence.

People buy JIRA. And then you've bought into the Atlassian ecosystem, and you want the nice tight integration with your wiki software

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#204

I look up to Atlassian. Somehow they continue to easily sell even though so many hates it. I don't know what the secret sauce is... but I want it.

It's like Microsoft in the 90s, everyone wants to hate on the company but their sales department just laughs and pens another huge contract

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#205
post #87

> The vulnerability only affects on-premise servers, not those hosted in the cloud. This is a dangerous statement to make and should be revised to say: > The vulnerability only affects standalone versions of the software, not the managed service of confluence provided directly by Atlassian. The problem with the former is that lesser technical people, especially directors, might assume they're fine because their stand…

Why do people say "on-premise" instead of "on-premises"?

Here follows the definitions I am familiar with:

"premise" - a house or building, together with its land and outbuildings, occupied by a business or considered in an official context.

"premise" - a previous statement or proposition from which another is inferred or follows as a conclusion.

(I have the privilege of worrying about this because my company uses Confluence Cloud. It's vastly inferior to our old aelf-hosted mediawiki, but at least it's not an open barn door.)

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#206

Earlier quoted context omitted.

This comment nails it - anyone who has had to investigate other offerings that satisfy the needs of project management, design, and engineering will quickly find that all the other options out there are total garbage in comparison to Jira, which is why Jira remains at the top of the totem pole for what it does. As an engineer & former manager, there are definitely things I didn't like about Jira like slowness, but ev…

My current company tried Monday. The engineers begged for Jira after that.

There's a worse world - one where you have on prem Jira, Monday, Paper, O365, Confluence, Github, and internal api documentation all out of alignment with the other. I'm begging to just end my misery.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#207
post #72

The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…

> The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. Regardless of what one thinks about Atlassian, this is a completely ridiculous bullshit statement, and anyone who works in the world of business software knows it. I don't think there is a company out there that hasn't had c…

I don't remember a company like whatsapp having this kind of problems.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#208

Why is Confluence so popular anyway? Why not just use any free wiki software?

It's easier for non-techs to pick up.

Confluence is often where the long-term docs for product/design oriented team members end up living, or at least being linked.

The easy two-way connection between Jira and confluence uses syntax any social media user will be familiar with, so non-techies can link the 'what' with the 'why' in a task before engineers even see them in a grooming session.

Anything that moves documentation and ticket preparation effort away from engineers/tech leads/team leads has a significant hidden saving.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#210
post #192

Can anyone comment on what the value of this attack is to the attackers?

Arbitrary code execution in an on-premise server? You can basically stage an attack on any other internal resources (core infrastructure, databases, endpoints) that are visible from there, with the benefit of already being behind at least one layer of firewall/security.
Post reply on HN