Earlier quoted context omitted.
Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.
> Need to run on-prem, it's mostly the wiki-like features I'm interested in. Since you are looking mostly for the wiki part there is Dokuwiki which is magnitudes better at being a wiki . Remember, wiki is derived from the Hawaiian word for quick or something to that effect and whatever Confluence is it isn't quick. Don't know how well it will hold up under scrutiny if black hats gets a reason to swarm over it, but un…
US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
41–50 of 344 posts
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#42Earlier quoted context omitted.
> Thankfully we had Crowdstrike on it which blocked any real damage For someone not familiar with their products, what did they do for you specifically?
For us specifically they blocked the server from downloading more assumedly dangerous tools. Blocked more privilege escalation and blocked crypto mining software from running. Our teams were also able to do a “network isolation” and essentially bring the server offline quickly, without touching more pieces and possibly exposing our credentials or tokens. We also had the paid Overwatch protection which is Crowdstrikes…
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#43I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.
Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#44Earlier quoted context omitted.
For those that believe in the zero trust model, don't all apps and services become exposed to the public internet?
They are generally exposed through a proxy that sits in between. If you don't authenticate, you can't send a request to it at all. (This is opposed to the lazy model, where your aplication is fully exposed to the web and you click log in and it redirects to SSO - if there is a vulnerability that doesn't require authentication you're already compromised) The proxy will handle sign in and passes traffic to/from the web…
I had the impression that in a zero trust environment all apps are required to be hardened to the point that they are deemed safe to be exposed to the publc internet.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#45Twitter link to a case of the vulnerability being exploited: https://twitter.com/th3_protoCOL/status/1433414685299142660 NIST Link to issue: https://nvd.nist.gov/vuln/detail/CVE-2021-26084 Tweet from USCYBERCOM urging users to patch: https://twitter.com/CNMF_CyberAlert/status/14337876717851852... Tweet from BadPackets showing where the bad actors are originating from: https://twitter.com/bad_packets/status/1433157632…
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#46I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.
Atlassian produce some of the worst tech on the planet. Trying to administer this crap is horrible.
And don't get me started on how many project managers spend all day staring at Jira tickets instead of actually talking to their teams. Management-by-Jira is a disease, a symptom of bad organisational culture.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#47Earlier quoted context omitted.
I didn't say that it is always the case. The same argument you use can be used to talk about companies who are going to self host Confluence. I agree that a lot of Saas startup are going to neglect security. But here we are talking about Knowledge base tools Saas companies. This is not some standard Saas company. They know they are in charge of company internal secrets. Or at lest I hope
Any time a SaaS gets compromised there's a similar comment here about how obviously this is going to happen when you give someone else your data, and it should have just all been within your own firewall, unexposed directly to the Internet. I mean right this minute there's a privacy-focused SaaS on the front page for not being as private as everyone thinks. There's also a network hardware vendor on the front page for…
I can't disagree with you. But you can either deny that the average Saas is more secure than a forgot Confluence internal servers exposed to the internet
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#48My employer was bit by this on Wednesday. Thankfully we had Crowdstrike on it which blocked any real damage. But it definitely moved our cloud migration from “later this year” to “later this month”. Also, not having confluence for a day exposed just how reliant we were on it for day-to-day activities.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#49I am not in the least bit shocked. Atlassian products are some of the worst glued-together garbage in the industry. The entire product surface area is probably rife with exploits. Using Confluence or Jira will show you just how much Atlassian cares about its own products. I'd love for this to be the straw that breaks the camel's back and makes IT/infosec orgs move away from this bilge.
I have no idea why you're being downvoted - this is true. Atlassian produce some of the worst tech on the planet. Trying to administer this crap is horrible. And don't get me started on how many project managers spend all day staring at Jira tickets instead of actually talking to their teams. Management-by-Jira is a disease, a symptom of bad organisational culture.
At some project size, measured either by software complexity/interoperability or user base, you will need a tool to manage issues and tasks.
What you're talking about is an organization where developers are not empowered - but even empowered developers need an issue tracker or a board of some description.
A "management by jira" culture will not be remediated by tooling.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#50Earlier quoted context omitted.
Any suggestions on what to use instead of Confluence? Need to run on-prem, it's mostly the wiki-like features I'm interested in.
> Need to run on-prem, it's mostly the wiki-like features I'm interested in. Since you are looking mostly for the wiki part there is Dokuwiki which is magnitudes better at being a wiki . Remember, wiki is derived from the Hawaiian word for quick or something to that effect and whatever Confluence is it isn't quick. Don't know how well it will hold up under scrutiny if black hats gets a reason to swarm over it, but un…