Live data from Hacker News

US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

zdnet.com

41–50 of 344 posts

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#41
post #6

Earlier quoted context omitted.

Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.

> Need to run on-prem, it's mostly the wiki-like features I'm interested in. Since you are looking mostly for the wiki part there is Dokuwiki which is magnitudes better at being a wiki . Remember, wiki is derived from the Hawaiian word for quick or something to that effect and whatever Confluence is it isn't quick. Don't know how well it will hold up under scrutiny if black hats gets a reason to swarm over it, but un…

For a non-technical user group you likely want something more WYSIWYG than Dokuwiki.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#42
post #17

Earlier quoted context omitted.

> Thankfully we had Crowdstrike on it which blocked any real damage For someone not familiar with their products, what did they do for you specifically?

For us specifically they blocked the server from downloading more assumedly dangerous tools. Blocked more privilege escalation and blocked crypto mining software from running. Our teams were also able to do a “network isolation” and essentially bring the server offline quickly, without touching more pieces and possibly exposing our credentials or tokens. We also had the paid Overwatch protection which is Crowdstrikes…

[deleted]

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#43
post #6
post #4

I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.

Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.

You can try Wiki.js or bookstack, both are open source and nice

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#44
post #14

Earlier quoted context omitted.

For those that believe in the zero trust model, don't all apps and services become exposed to the public internet?

They are generally exposed through a proxy that sits in between. If you don't authenticate, you can't send a request to it at all. (This is opposed to the lazy model, where your aplication is fully exposed to the web and you click log in and it redirects to SSO - if there is a vulnerability that doesn't require authentication you're already compromised) The proxy will handle sign in and passes traffic to/from the web…

Do these proxies encrypt the traffic? Since they would handle authentication, I am guessing encryption is used. We may be getting into semantics, but at that point, is there much of a difference between a proxy and a VPN?

I had the impression that in a zero trust environment all apps are required to be hardened to the point that they are deemed safe to be exposed to the publc internet.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#45
post #2

Twitter link to a case of the vulnerability being exploited: https://twitter.com/th3_protoCOL/status/1433414685299142660 NIST Link to issue: https://nvd.nist.gov/vuln/detail/CVE-2021-26084 Tweet from USCYBERCOM urging users to patch: https://twitter.com/CNMF_CyberAlert/status/14337876717851852... Tweet from BadPackets showing where the bad actors are originating from: https://twitter.com/bad_packets/status/1433157632…

Nit: I wouldn't say "originating". That's where this specific exploit is coming from "most recently". But it would seem to not be script kiddies and they're listing like 8 countries. I would assume the bad actors could be anywhere, proxying traffic through any number of other places.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#46
post #4

I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.

I have no idea why you're being downvoted - this is true.

Atlassian produce some of the worst tech on the planet. Trying to administer this crap is horrible.

And don't get me started on how many project managers spend all day staring at Jira tickets instead of actually talking to their teams. Management-by-Jira is a disease, a symptom of bad organisational culture.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#47
post #40
post #30

Earlier quoted context omitted.

I didn't say that it is always the case. The same argument you use can be used to talk about companies who are going to self host Confluence. I agree that a lot of Saas startup are going to neglect security. But here we are talking about Knowledge base tools Saas companies. This is not some standard Saas company. They know they are in charge of company internal secrets. Or at lest I hope

Any time a SaaS gets compromised there's a similar comment here about how obviously this is going to happen when you give someone else your data, and it should have just all been within your own firewall, unexposed directly to the Internet. I mean right this minute there's a privacy-focused SaaS on the front page for not being as private as everyone thinks. There's also a network hardware vendor on the front page for…

If you can afford to not expose it to the internet obviously you are going to have better security. But this is not always desirable talking about wiki software.

I can't disagree with you. But you can either deny that the average Saas is more secure than a forgot Confluence internal servers exposed to the internet

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#48

My employer was bit by this on Wednesday. Thankfully we had Crowdstrike on it which blocked any real damage. But it definitely moved our cloud migration from “later this year” to “later this month”. Also, not having confluence for a day exposed just how reliant we were on it for day-to-day activities.

Security is planning to implement here CrowdStrike in the near future... does it run on every single server?

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#49
post #4

I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.

I have no idea why you're being downvoted - this is true. Atlassian produce some of the worst tech on the planet. Trying to administer this crap is horrible. And don't get me started on how many project managers spend all day staring at Jira tickets instead of actually talking to their teams. Management-by-Jira is a disease, a symptom of bad organisational culture.

But jira is only a tool right? Blaming Atlassian for a poorly led organization seems slightly misguided.

At some project size, measured either by software complexity/interoperability or user base, you will need a tool to manage issues and tasks.

What you're talking about is an organization where developers are not empowered - but even empowered developers need an issue tracker or a board of some description.

A "management by jira" culture will not be remediated by tooling.

Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing

#50
post #6

Earlier quoted context omitted.

Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.

> Need to run on-prem, it's mostly the wiki-like features I'm interested in. Since you are looking mostly for the wiki part there is Dokuwiki which is magnitudes better at being a wiki . Remember, wiki is derived from the Hawaiian word for quick or something to that effect and whatever Confluence is it isn't quick. Don't know how well it will hold up under scrutiny if black hats gets a reason to swarm over it, but un…

I'm betting the downvotes are Atlassian employees attempting damage limitation / astroturfing.
Post reply on HN